Information | Value |
---|---|
Trigger | usbehub.sys |
Start Address | 0xfffff88003908d40 |
Information | Value |
---|---|
Sequence Length | 211 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
RtlInitUnicodeString | SourceString = \Device\VBoxDrv, DestinationString_out = \Device\VBoxDrv |
IoCreateDevice | DriverObject_unk = 0xfffffa8002fcb5d0, DeviceExtensionSize = 0x1108, DeviceName = \Device\VBoxDrv, DeviceType_unk = 0x22, DeviceCharacteristics = 0x0, Exclusive = 0, DeviceObject_unk_out = 0xfffff88004789870, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = \DosDevices\VBoxDrv, DestinationString_out = \DosDevices\VBoxDrv |
IoCreateSymbolicLink | SymbolicLinkName = \DosDevices\VBoxDrv, DeviceName = \Device\VBoxDrv, ret_val_unk_out = 0x0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x20, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8001f5a870 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x50, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8003126570 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80031265a0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x50, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8003074780 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80030747b0 |
KeQueryActiveProcessors | ret_val_unk_out = 0x1 |
MmAllocateContiguousMemory | NumberOfBytes_ptr = 0x1000, HighestAcceptableAddress_unk = 0xffffffff, ret_val_ptr_out = 0xfffffa8001927000 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffffa8001927000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003209a00 |
MmBuildMdlForNonPagedPool | MemoryDescriptorList_unk = 0xfffffa8003209a00, MemoryDescriptorList_unk_out = 0xfffffa8003209a00 |
ExSetTimerResolution | DesiredTime = 0x2625a, SetResolution = 1, ret_val_out = 0x26161 |
ExSetTimerResolution | DesiredTime = 0x0, SetResolution = 0, ret_val_out = 0x26161 |
KeQueryActiveProcessors | ret_val_unk_out = 0x1 |
MmGetPhysicalAddress | BaseAddress_ptr = 0xfffffa8001927000, ret_val_unk_out = 0x7fe21000 |
KeInitializeTimerEx | Type_unk = 0x1, Timer_unk_out = 0xfffffa8003167210 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff880039085b0, DeferredContext_ptr = 0xfffffa80031671a0, Dpc_unk_out = 0xfffffa8003167250 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167290 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167290, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167290 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167290, Number = 0, Dpc_unk_out = 0xfffffa8003167290 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031672d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031672d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031672d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031672d0, Number = 1, Dpc_unk_out = 0xfffffa80031672d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167310 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167310, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167310 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167310, Number = 2, Dpc_unk_out = 0xfffffa8003167310 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167350 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167350, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167350 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167350, Number = 3, Dpc_unk_out = 0xfffffa8003167350 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167390 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167390, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167390 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167390, Number = 4, Dpc_unk_out = 0xfffffa8003167390 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031673d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031673d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031673d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031673d0, Number = 5, Dpc_unk_out = 0xfffffa80031673d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167410 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167410, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167410 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167410, Number = 6, Dpc_unk_out = 0xfffffa8003167410 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167450 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167450, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167450 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167450, Number = 7, Dpc_unk_out = 0xfffffa8003167450 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167490 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167490, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167490 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167490, Number = 8, Dpc_unk_out = 0xfffffa8003167490 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031674d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031674d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031674d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031674d0, Number = 9, Dpc_unk_out = 0xfffffa80031674d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167510 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167510, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167510 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167510, Number = 10, Dpc_unk_out = 0xfffffa8003167510 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167550 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167550, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167550 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167550, Number = 11, Dpc_unk_out = 0xfffffa8003167550 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167590 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167590, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167590 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167590, Number = 12, Dpc_unk_out = 0xfffffa8003167590 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031675d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031675d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031675d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031675d0, Number = 13, Dpc_unk_out = 0xfffffa80031675d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167610 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167610, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167610 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167610, Number = 14, Dpc_unk_out = 0xfffffa8003167610 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167650 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167650, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167650 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167650, Number = 15, Dpc_unk_out = 0xfffffa8003167650 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167690 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167690, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167690 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167690, Number = 16, Dpc_unk_out = 0xfffffa8003167690 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031676d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031676d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031676d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031676d0, Number = 17, Dpc_unk_out = 0xfffffa80031676d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167710 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167710, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167710 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167710, Number = 18, Dpc_unk_out = 0xfffffa8003167710 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167750 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167750, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167750 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167750, Number = 19, Dpc_unk_out = 0xfffffa8003167750 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167790 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167790, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167790 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167790, Number = 20, Dpc_unk_out = 0xfffffa8003167790 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031677d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031677d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031677d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031677d0, Number = 21, Dpc_unk_out = 0xfffffa80031677d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167810 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167810, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167810 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167810, Number = 22, Dpc_unk_out = 0xfffffa8003167810 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167850 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167850, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167850 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167850, Number = 23, Dpc_unk_out = 0xfffffa8003167850 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167890 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167890, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167890 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167890, Number = 24, Dpc_unk_out = 0xfffffa8003167890 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031678d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031678d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031678d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031678d0, Number = 25, Dpc_unk_out = 0xfffffa80031678d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167910 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167910, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167910 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167910, Number = 26, Dpc_unk_out = 0xfffffa8003167910 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167950 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167950, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167950 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167950, Number = 27, Dpc_unk_out = 0xfffffa8003167950 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167990 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167990, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167990 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167990, Number = 28, Dpc_unk_out = 0xfffffa8003167990 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031679d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031679d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031679d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031679d0, Number = 29, Dpc_unk_out = 0xfffffa80031679d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167a10 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167a10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167a10 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167a10, Number = 30, Dpc_unk_out = 0xfffffa8003167a10 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167a50 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167a50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167a50 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167a50, Number = 31, Dpc_unk_out = 0xfffffa8003167a50 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167a90 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167a90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167a90 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167a90, Number = 32, Dpc_unk_out = 0xfffffa8003167a90 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167ad0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167ad0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167ad0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167ad0, Number = 33, Dpc_unk_out = 0xfffffa8003167ad0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167b10 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167b10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167b10 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167b10, Number = 34, Dpc_unk_out = 0xfffffa8003167b10 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167b50 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167b50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167b50 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167b50, Number = 35, Dpc_unk_out = 0xfffffa8003167b50 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167b90 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167b90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167b90 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167b90, Number = 36, Dpc_unk_out = 0xfffffa8003167b90 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167bd0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167bd0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167bd0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167bd0, Number = 37, Dpc_unk_out = 0xfffffa8003167bd0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167c10 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167c10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167c10 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167c10, Number = 38, Dpc_unk_out = 0xfffffa8003167c10 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167c50 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167c50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167c50 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167c50, Number = 39, Dpc_unk_out = 0xfffffa8003167c50 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167c90 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167c90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167c90 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167c90, Number = 40, Dpc_unk_out = 0xfffffa8003167c90 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167cd0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167cd0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167cd0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167cd0, Number = 41, Dpc_unk_out = 0xfffffa8003167cd0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167d10 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167d10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167d10 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167d10, Number = 42, Dpc_unk_out = 0xfffffa8003167d10 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167d50 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167d50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167d50 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167d50, Number = 43, Dpc_unk_out = 0xfffffa8003167d50 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167d90 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167d90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167d90 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167d90, Number = 44, Dpc_unk_out = 0xfffffa8003167d90 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167dd0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167dd0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167dd0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167dd0, Number = 45, Dpc_unk_out = 0xfffffa8003167dd0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167e10 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167e10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167e10 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167e10, Number = 46, Dpc_unk_out = 0xfffffa8003167e10 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167e50 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167e50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167e50 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167e50, Number = 47, Dpc_unk_out = 0xfffffa8003167e50 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167e90 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167e90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167e90 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167e90, Number = 48, Dpc_unk_out = 0xfffffa8003167e90 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167ed0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167ed0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167ed0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167ed0, Number = 49, Dpc_unk_out = 0xfffffa8003167ed0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167f10 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167f10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167f10 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167f10, Number = 50, Dpc_unk_out = 0xfffffa8003167f10 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167f50 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167f50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167f50 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167f50, Number = 51, Dpc_unk_out = 0xfffffa8003167f50 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167f90 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167f90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167f90 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167f90, Number = 52, Dpc_unk_out = 0xfffffa8003167f90 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167fd0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003167fd0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167fd0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003167fd0, Number = 53, Dpc_unk_out = 0xfffffa8003167fd0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168010 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003168010, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168010 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003168010, Number = 54, Dpc_unk_out = 0xfffffa8003168010 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168050 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003168050, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168050 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003168050, Number = 55, Dpc_unk_out = 0xfffffa8003168050 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168090 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003168090, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168090 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003168090, Number = 56, Dpc_unk_out = 0xfffffa8003168090 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031680d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031680d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031680d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031680d0, Number = 57, Dpc_unk_out = 0xfffffa80031680d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168110 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003168110, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168110 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003168110, Number = 58, Dpc_unk_out = 0xfffffa8003168110 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168150 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003168150, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168150 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003168150, Number = 59, Dpc_unk_out = 0xfffffa8003168150 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168190 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003168190, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168190 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003168190, Number = 60, Dpc_unk_out = 0xfffffa8003168190 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031681d0 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa80031681d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031681d0 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa80031681d0, Number = 61, Dpc_unk_out = 0xfffffa80031681d0 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168210 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003168210, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168210 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003168210, Number = 62, Dpc_unk_out = 0xfffffa8003168210 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168250 |
KeSetImportanceDpc | Dpc_unk = 0xfffffa8003168250, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168250 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffffa8003168250, Number = 63, Dpc_unk_out = 0xfffffa8003168250 |
Information | Value |
---|---|
Trigger | IofCallDriver+0x50 |
Start Address | 0xfffff88003908980 |
Information | Value |
---|---|
Sequence Length | 5 |
Process | Amount |
---|---|
Process 35 (pxinsi64.exe, PID: 1228) | 1 |
Symbol | Parameters |
---|---|
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x678, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8001952980 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x20, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa800186dd80 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4cc |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
Information | Value |
---|---|
Trigger | IofCallDriver+0x50 |
Start Address | 0xfffff88003908af0 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 35 (pxinsi64.exe, PID: 1228) | 1 |
Symbol | Parameters |
---|---|
IoIs32bitProcess | Irp_unk = 0xfffffa8002e2ad00, ret_val_out = 0 |
strncmp | _Str1 = The Magic Word!, _Str2 = The Magic Word!, _MaxCount = 0x10, ret_val_out = 0 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
Information | Value |
---|---|
Sequence Length | 7 |
Process | Amount |
---|---|
Process 35 (pxinsi64.exe, PID: 1228) | 1 |
Symbol | Parameters |
---|---|
IoIs32bitProcess | Irp_unk = 0xfffffa8002e2ad00, ret_val_out = 0 |
memchr | _Buf_ptr = 0xfffffa800316255c, _Val = 0, _MaxCount = 0x20, ret_val_ptr_out = 0xfffffa800316255d |
ExAcquireFastMutex | FastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0xaf, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa80031626b0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x28, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8002ed4160 |
ExReleaseFastMutex | FastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
Information | Value |
---|---|
Sequence Length | 4 |
Process | Amount |
---|---|
Process 35 (pxinsi64.exe, PID: 1228) | 1 |
Symbol | Parameters |
---|---|
IoIs32bitProcess | Irp_unk = 0xfffffa8002e2ad00, ret_val_out = 0 |
ExAcquireFastMutex | FastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588 |
ExReleaseFastMutex | FastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
Information | Value |
---|---|
Sequence Length | 2 |
Process | Amount |
---|---|
Process 35 (pxinsi64.exe, PID: 1228) | 1 |
Symbol | Parameters |
---|---|
IoIs32bitProcess | Irp_unk = 0xfffffa8002e2ad00, ret_val_out = 0 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 35 (pxinsi64.exe, PID: 1228) | 1 |
Symbol | Parameters |
---|---|
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
Information | Value |
---|---|
Trigger | IofCallDriver+0x50 |
Start Address | 0xfffff88003908390 |
Information | Value |
---|---|
Sequence Length | 7 |
Process | Amount |
---|---|
Process 35 (pxinsi64.exe, PID: 1228) | 1 |
Symbol | Parameters |
---|---|
ExAcquireFastMutex | FastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588 |
ExFreePoolWithTag | P_ptr = 0xfffffa80031626b0, Tag = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffffa8002ed4160, Tag = 0x0 |
ExReleaseFastMutex | FastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588 |
ExFreePoolWithTag | P_ptr = 0xfffffa800186dd80, Tag = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffffa8001952980, Tag = 0x0 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
Information | Value |
---|---|
Trigger | IopLoadUnloadDriver+0x19 |
Start Address | 0xfffff880039088b0 |
Information | Value |
---|---|
Sequence Length | 9 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
RtlInitUnicodeString | SourceString = \DosDevices\VBoxDrv, DestinationString_out = \DosDevices\VBoxDrv |
IoDeleteSymbolicLink | SymbolicLinkName = \DosDevices\VBoxDrv, ret_val_unk_out = 0x0 |
KeCancelTimer | param_1_unk = 0xfffffa8003167210, param_1_unk_out = 0xfffffa8003167210, ret_val_out = 0 |
IoFreeMdl | Mdl_unk = 0xfffffa8003209a00 |
MmFreeContiguousMemory | BaseAddress_ptr = 0xfffffa8001927000 |
ExFreePoolWithTag | P_ptr = 0xfffffa8003074780, Tag = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffffa8003126570, Tag = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffffa8001f5a870, Tag = 0x0 |
IoDeleteDevice | DeviceObject_unk = 0xfffffa8003167050 |
Information | Value |
---|---|
Trigger | IopLoadDriver+0xa04 |
Start Address | 0xfffff88004895be0 |
Information | Value |
---|---|
Sequence Length | 603 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x10, Tag = 0x4895544, ret_val_ptr_out = 0xfffffa8002ec3a40 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0xc0000004 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0xc0000004 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0xc0000004 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExFreePoolWithTag | P_ptr = 0xfffffa8002ec3a40, Tag = 0x4895544 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047897a8, ret_val_unk_out = 0xc0000004 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047897a8, ret_val_unk_out = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
RtlQueryRegistryValues | RelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff88004789780, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0 |
RtlNtStatusToDosError | Status_unk = 0x0, ret_val_out = 0x0 |
ZwOpenEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880047895a0, EventHandle_ptr_out = 0xfffff88004789810, ret_val_unk_out = 0xc0000034 |
_snwprintf | _Count = 0x104, _Format = \BaseNamedObjects\%S, _Dest_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, ret_val_out = 62 |
RtlInitUnicodeString | SourceString = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, DestinationString_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153} |
ZwOpenEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880047895a0, EventHandle_ptr_out = 0xfffff88004789810, ret_val_unk_out = 0xc0000034 |
PsGetVersion | MajorVersion_ptr_out = 0xfffff88004789528, MinorVersion_ptr_out = 0xfffff88004789520, BuildNumber_ptr_out = 0x0, CSDVersion_ptr_out = 0x0, ret_val_out = 0 |
RtlLengthRequiredSid | SubAuthorityCount = 0x1, ret_val_out = 0xc |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x44, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a000dbfc00 |
RtlCreateSecurityDescriptor | Revision = 0x1, SecurityDescriptor_unk_out = 0xfffff8a000dbfc00, ret_val_unk_out = 0x0 |
RtlSetDaclSecurityDescriptor | DaclPresent = 1, Dacl_unk = 0x0, DaclDefaulted = 0, SecurityDescriptor_unk_out = 0xfffff8a000dbfc00, ret_val_unk_out = 0x0 |
ZwCreateEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880047895a0, EventType_unk = 0x0, InitialState = 0, EventHandle_ptr_out = 0xfffff8800486f5b8, ret_val_unk_out = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffff8a000dbfc00, Tag = 0x7346744e |
PsCreateSystemThread | DesiredAccess = 0x0, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffff8800482303c, StartContext_ptr = 0xfffff880048708d4, ThreadHandle_ptr_out = 0xfffff88004789818, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 |
ZwWaitForSingleObject | Handle_unk = 0xffffffff80000824, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x87000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8001bbe000 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff88004789708, ret_val_unk_out = 0xc0000004 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff88004789708, ret_val_unk_out = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
RtlQueryRegistryValues | RelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff880047896e0, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0 |
RtlNtStatusToDosError | Status_unk = 0x0, ret_val_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026ec860, Length = 0x7a0, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003209a00 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003209a00, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8003209a00 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026ed000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x60, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002e556a0 |
sprintf | _Format = %02x, _Dest_out = 65, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 04, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 25, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 88, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 80, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f6, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c3, ret_val_out = 2 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003209a00, MemoryDescriptorList_unk_out = 0xfffffa8003209a00 |
IoFreeMdl | Mdl_unk = 0xfffffa8003209a00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff88004789508, ret_val_unk_out = 0xc0000004 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000 |
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff88004789508, ret_val_unk_out = 0x0 |
_vsnprintf | count = 0x104, format = \SystemRoot\system32\%s, ap_unk = 0xfffff88004789518, string_out = \SystemRoot\system32\ntoskrnl.exe, ret_val_out = 33 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x20a, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f435e0 |
mbstowcs | _Source = \SystemRoot\system32\ntoskrnl.exe, _MaxCount = 0x104, _Dest_out = \SystemRoot\system32\ntoskrnl.exe, ret_val_unk_out = 0x21 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x208, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001635bd0 |
wcsncpy | _Source = \SystemRoot\system32\ntoskrnl.exe, _Count = 0x104, _Dest_out = \SystemRoot\system32\ntoskrnl.exe, ret_val_out = \SystemRoot\system32\ntoskrnl.exe |
RtlInitUnicodeString | SourceString = \SystemRoot\system32\ntoskrnl.exe, DestinationString_out = \SystemRoot\system32\ntoskrnl.exe |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880047893b8, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\system32\ntoskrnl.exe, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff88004789390, FileHandle_out = 0xffffffff80000824, IoStatusBlock_unk_out = 0xfffff880047893a8, ret_val_unk_out = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001635bd0, Tag = 0x7346744e |
ZwQueryInformationFile | FileHandle_unk = 0xffffffff80000824, Length = 0x18, FileInformationClass_unk = 0x5, IoStatusBlock_unk_out = 0xfffff880047893e0, FileInformation_ptr_out = 0xfffff880047893f0, ret_val_unk_out = 0x0 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x54bfc0, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a002000000 |
ZwReadFile | FileHandle_unk = 0xffffffff80000824, Event_unk = 0x0, UserApcRoutine_unk = 0x0, UserApcContext_ptr = 0x0, BufferLength = 0x54bfc0, ByteOffset_ptr = 0xfffff88004789438, ByteOffset = -2, Key_ptr = 0x0, IoStatusBlock_unk_out = 0xfffff88004789400, Buffer_ptr_out = 0xfffff8a002000000, Buffer_deref_data_out = BINARY(offset=108056959,skipped=1,size=0), ret_val_unk_out = 0x0 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x5e7000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a002600000 |
ExFreePoolWithTag | P_ptr = 0xfffff8a002000000, Tag = 0x7346744e |
ZwClose | Handle_unk = 0x0, ret_val_unk_out = 0xc0000008 |
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f435e0, Tag = 0x7346744e |
ExFreePoolWithTag | P_ptr = 0xfffff8a001f17000, Tag = 0x7346744e |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88007fad000 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fad000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0xc88, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f4b010 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0xe0, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa80018506f0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x2c, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002eb0220 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8002eb0200 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8002eb0200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff80000b95c02, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
ExFreePoolWithTag | P_ptr = 0xfffffa8002eb0220, Tag = 0x7346744e |
ExAllocatePoolWithTag | PoolType_unk = 0x1, NumberOfBytes_ptr = 0x104, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001858010 |
ExFreePoolWithTag | P_ptr = 0xfffff8a001858010, Tag = 0x7346744e |
ZwClose | Handle_unk = 0x0, ret_val_unk_out = 0xc0000008 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff800026f6902, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0xe0, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002fc9600 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 54, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 54, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026f6920, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x10, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002ec3a40 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x28, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002eb0220 |
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0xe0, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa800202f300 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f5, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 41, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 81, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f5, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 41, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 81, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 41, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 81, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 80, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 41, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 81, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 80, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4800, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = fd, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 2e, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 64, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 38, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 84, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 80, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 64, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 38, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 84, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 80, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c5060, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 9d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 26, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 45, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 45, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 43, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 45, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 45, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 43, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4920, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 2d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 23, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 38, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 65, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 04, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 25, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 88, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 90, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f6, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 38, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 65, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 04, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 25, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 88, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 90, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f6, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c49e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 2d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 29, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 54, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 54, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
strncpy | _Source = $NtUninstallQ923283$, _Count = 0x64, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$ |
_snwprintf | _Count = 0x104, _Format = \SystemRoot\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$, ret_val_out = 32 |
strncpy | _Source = fdisk.sys, _Count = 0x64, _Dest_out = fdisk.sys, ret_val_out = fdisk.sys |
_snwprintf | _Count = 0x104, _Format = %s\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$\fdisk.sys, ret_val_out = 42 |
RtlInitUnicodeString | SourceString = \SystemRoot\$NtUninstallQ923283$, DestinationString_out = \SystemRoot\$NtUninstallQ923283$ |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff88004788ef0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x2, ShareAccess = 0x0, Disposition = 0x2, CreateOptions = 0x21, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x700000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880047896a0, FileHandle_out = 0xfffffa8002e516c0, IoStatusBlock_unk_out = 0xfffff88004788fa0, ret_val_unk_out = 0xc0000035 |
_snprintf | _Count = 0x64, _Format = %s, _Dest_out = Ultra3, ret_val_out = 6 |
_snwprintf | _Count = 0x104, _Format = \Registry\Machine\System\CurrentControlSet\Services\%S, _Dest_out = \Registry\Machine\System\CurrentControlSet\Services\Ultra3, ret_val_out = 58 |
RtlInitUnicodeString | SourceString = \Registry\Machine\System\CurrentControlSet\Services\Ultra3, DestinationString_out = \Registry\Machine\System\CurrentControlSet\Services\Ultra3 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
strncpy | _Source = $NtUninstallQ923283$, _Count = 0x64, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$ |
_snwprintf | _Count = 0x104, _Format = %%SystemRoot%%\%S, _Dest_out = %SystemRoot%\$NtUninstallQ923283$, ret_val_out = 33 |
strncpy | _Source = fdisk_mon.exe, _Count = 0x64, _Dest_out = fdisk_mon.exe, ret_val_out = fdisk_mon.exe |
_snwprintf | _Count = 0x104, _Format = %s\%S, _Dest_out = %SystemRoot%\$NtUninstallQ923283$\fdisk_mon.exe, ret_val_out = 47 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
ZwFlushKey | KeyHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 |
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc8880, StartContext_ptr = 0x0, ThreadHandle_ptr_out = 0xfffff880047895a0, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 |
ZwWaitForSingleObject | Handle_unk = 0xffffffff80000824, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 |
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a000307c00, ThreadHandle_ptr_out = 0xfffff88004789610, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 |
ZwWaitForSingleObject | Handle_unk = 0xffffffff80000824, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 |
KeInitializeEvent | Type_unk = 0x0, State = 0, Event_unk_out = 0xfffff88004789610 |
KeInitializeDpc | DeferredRoutine_unk = 0xfffffa8001bc4130, DeferredContext_ptr = 0xfffff88004789610, Dpc_unk_out = 0xfffff88004789630 |
KeSetImportanceDpc | Dpc_unk = 0xfffff88004789630, Importance_unk = 0x2, Dpc_unk_out = 0xfffff88004789630 |
KeSetTargetProcessorDpc | Dpc_unk = 0xfffff88004789630, Number = 0, Dpc_unk_out = 0xfffff88004789630 |
KeInsertQueueDpc | Dpc_unk = 0xfffff88004789630, SystemArgument1_ptr = 0x0, SystemArgument2_ptr = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffff88004789610, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a54200, Length = 0x100, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003209a00 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003209a00, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8003209a00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff800026cc502, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 38, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 38, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026cc550, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff800026d7502, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026d75f0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
ZwOpenKey | DesiredAccess_unk = 0x2, ObjectAttributes_ptr = 0xfffff88004789710, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\System\CurrentControlSet\Control\Session Manager\Memory Management, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880047896c0, KeyHandle_out = 0xffffffff80000824, ret_val_unk_out = 0x0 |
ZwSetValueKey | KeyHandle_unk = 0xffffffff80000824, ValueName = LargePageMinimum, TitleIndex = 0x0, Type = 0x4, Data_ptr = 0xfffff88004789780, Data = 0xffffffff, DataSize = 0x4, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff800026d6102, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026d6180, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff80002939002, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029390c0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a000307c00, ThreadHandle_ptr_out = 0xfffff88004789740, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | PspSystemThreadStartup+0x57 |
Start Address | 0xfffff8800482303c |
Information | Value |
---|---|
Sequence Length | 2 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsTerminateSystemThread | ExitStatus_unk = 0x0 |
Information | Value |
---|---|
Trigger | PspSystemThreadStartup+0x57 |
Start Address | 0xfffffa8001bc8880 |
Information | Value |
---|---|
Sequence Length | 2 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8003177620 |
PsTerminateSystemThread | ExitStatus_unk = 0x0 |
Information | Value |
---|---|
Trigger | PspSystemThreadStartup+0x57 |
Start Address | 0xfffffa8001bc88f4 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 3 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002f81b50 |
rand | ret_val_out = 17888 |
PsTerminateSystemThread | ExitStatus_unk = 0x0 |
Information | Value |
---|---|
Sequence Length | 2199 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa80030e9a00 | ||||
rand | ret_val_out = 12425 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
PsCreateSystemThread | DesiredAccess = 0x0, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bdfef4, StartContext_ptr = 0xfffffa8001c2d8d0, ThreadHandle_ptr_out = 0xfffff880022c9b48, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ZwWaitForSingleObject | Handle_unk = 0xffffffff800007f4, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ZwClose | Handle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 | ||||
strncpy | _Source = System, _Count = 0x11, _Dest_out = System, ret_val_out = System | ||||
RtlInitUnicodeString | SourceString = \Device\Null, DestinationString_out = \Device\Null | ||||
IoGetDeviceObjectPointer | ObjectName = \Device\Null, DesiredAccess_unk = 0x0, FileObject_unk_out = 0xfffff880022c9b40, DeviceObject_unk_out = 0xfffffa8001c2c540, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002516740, ret_val_ptr_out = 0x3 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002db2820 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002f64ce0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8003062510 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002e55aa0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002f7f7b0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa800303a160 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8003133510 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4720, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 13, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b56000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b56000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff8000299db02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8000299db60, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4aa0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b57000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b57000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002986d02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002986df0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4800, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2e, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b58000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b58000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002982802, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002982820, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c6de0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 09, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b59000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b59000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002b4f402, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002b4f440, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4520, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 31, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 03, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5a000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5a000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029b7f02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029b7f80, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4b20, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 33, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5b000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5b000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029d9c02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029d9cdc, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4780, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 7d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 16, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5c000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5c000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029e0702, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029e0780, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4640, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 0c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5d000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5d000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029c5702, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029c5740, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c49e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 29, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5e000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5e000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002987d02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002987d14, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029ca602, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029ca650, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
ZwOpenEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0xc0000034 | ||||
_snwprintf | _Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk1, ret_val_out = 16 | ||||
_snwprintf | _Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk2, ret_val_out = 16 | ||||
_snprintf | _Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par1, ret_val_out = 8 | ||||
_swprintf | _Format = %S, _Dest_out = \??\Par1, ret_val_out = 8 | ||||
_snprintf | _Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par2, ret_val_out = 8 | ||||
_swprintf | _Format = %S, _Dest_out = \??\Par2, ret_val_out = 8 | ||||
_snwprintf | _Count = 0x104, _Format = \BaseNamedObjects\%S, _Dest_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, ret_val_out = 62 | ||||
RtlInitUnicodeString | SourceString = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, DestinationString_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153} | ||||
ZwOpenEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0x0 | ||||
ZwClose | Handle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9560, Object_out = 0xfffffa8002dd1890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dd1890, ret_val_ptr_out = 0x5 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
RtlQueryRegistryValues | RelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff880022c9970, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9660, Object_out = 0xfffff8a0013e0c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013e0c50, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
RtlNtStatusToDosError | Status_unk = 0x0, ret_val_out = 0x0 | ||||
RtlInitUnicodeString | SourceString = \SystemRoot, DestinationString_out = \SystemRoot | ||||
ZwOpenSymbolicLinkObject | DesiredAccess_unk = 0x1, ObjectAttributes_unk = 0xfffff880022c96d0, SymbolicLinkHandle_ptr_out = 0xfffff880022c99a0, ret_val_unk_out = 0x0 | ||||
ZwQuerySymbolicLinkObject | SymLinkObjHandle_unk = 0xffffffff800007f4, LinkTarget_out = \Device\Harddisk0\Partition2\Windows, DataWritten_ptr_out = 0x0, ret_val_unk_out = 0x0 | ||||
wcsncpy | _Source = Windows, _Count = 0x104, _Dest_out = Windows, ret_val_out = Windows | ||||
strncpy | _Source = $NtUninstallQ923283$, _Count = 0x52, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$ | ||||
_snwprintf | _Count = 0x51, _Format = %S, _Dest_out = $NtUninstallQ923283$, ret_val_out = 20 | ||||
_snwprintf | _Count = 0x103, _Format = \SystemRoot\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$, ret_val_out = 32 | ||||
RtlInitUnicodeString | SourceString = \SystemRoot\$NtUninstallQ923283$, DestinationString_out = \SystemRoot\$NtUninstallQ923283$ | ||||
ZwOpenFile | DesiredAccess_unk = 0x100000, ObjectAttributes_ptr = 0xfffff880022c96d0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$, ObjectAttributes_deref_Attributes = 0x240, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, ShareAccess = 0x7, OpenOptions = 0x21, FileHandle_ptr_out = 0xfffff880022c99a0, FileHandle_out = 0xffffffff80000824, IoStatusBlock_unk_out = 0xfffff880022c9700, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c99a8, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa800202b650, ret_val_ptr_out = 0xa | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002c55030, ret_val_ptr_out = 0x2 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9490, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80026b7660 | ||||
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001ecfc00, ThreadHandle_ptr_out = 0xfffffa8001c2c210, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000004 | ||||
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9530, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030e9a00 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x779a17b0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b5f000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5f000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x779a17e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b60000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 38 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa800311f640 |
rand | ret_val_out = 25331 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002fc83c0 |
rand | ret_val_out = 11502 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80031273d0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0 |
Information | Value |
---|---|
Sequence Length | 82 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8003177620 |
rand | ret_val_out = 5970 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001b865b8, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001b86598 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
RtlInitAnsiString | DestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0 |
RtlAnsiStringToUnicodeString | DestinationString_ptr = 0xfffff8a001820b78, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001820b88, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001820b68 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
RtlInitAnsiString | DestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0 |
RtlAnsiStringToUnicodeString | DestinationString_ptr = 0xfffff8a001e9a708, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001e9a718, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001e9a6f8 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000 |
Information | Value |
---|---|
Sequence Length | 1613 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002e72880 | ||||
rand | ret_val_out = 14463 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800435e000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800437b000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002ff5cd8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e64000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9c000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9d000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ec9000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eca000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecb000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecc000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecd000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ece000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecf000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed0000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed1000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed2000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed3000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed4000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed5000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed6000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed7000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed8000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed9000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eda000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edb000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edc000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edd000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ede000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edf000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee0000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee1000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee3000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eec000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x3293e00, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x3293000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0xc0000054 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b93000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b97000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x94000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x94000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9b000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9c000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9d000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9e000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9f000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000bb0000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0xc88fe00, RegionSize_ptr = 0xfffff880045bbb58 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f18c78 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8001ae4000, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88004800000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Trigger | PspSystemThreadStartup+0x57 |
Start Address | 0xfffffa8001bdfef4 |
Information | Value |
---|---|
Sequence Length | 739 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 91 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = HH , _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 101 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -107 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 106 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 107 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = 99 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -105 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -3 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -25 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -27 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = 63 |
_strnicmp | _Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 103 |
_strnicmp | _Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -90 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -97 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -88 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -110 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -94 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -69 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -105 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -98 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -20 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = /, _MaxCount = 0x6, ret_val_out = 68 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -70 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -18 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -77 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = -93 |
_strnicmp | _Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = 8 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 90 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = 8 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 97 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -28 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = -125 |
_strnicmp | _Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = 19 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -139 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -87 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -4 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = System, _MaxCount = 0x6, ret_val_out = 0 |
PsTerminateSystemThread | ExitStatus_unk = 0x0 |
Information | Value |
---|---|
Trigger | KiRetireDpcList+0x1b5 |
Start Address | 0xfffffa8001bc4130 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeSetEvent | Event_unk = 0xfffff88004789610, Increment_unk = 0x0, Wait = 0 |
Information | Value |
---|---|
Trigger | IofCallDriver+0x2 |
Start Address | 0xfffffa8001c02000 |
Information | Value |
---|---|
Sequence Length | 24 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 8 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 27 |
Process 18 (svchost.exe, PID: 264) | 1 |
Process 4 (csrss.exe, PID: 304) | 52 |
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 84 |
Process | Amount |
---|---|
Process 4 (csrss.exe, PID: 304) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 12 |
Process | Amount |
---|---|
Process 4 (csrss.exe, PID: 304) | 12 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 78 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 7 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 5 |
Process 2 (System, PID: 4) | 163 |
Process 4 (csrss.exe, PID: 304) | 51 |
Process 6 (csrss.exe, PID: 364) | 4 |
Process 8 (services.exe, PID: 448) | 43 |
Process 9 (lsass.exe, PID: 464) | 208 |
Process 10 (lsm.exe, PID: 472) | 13 |
Process 11 (svchost.exe, PID: 564) | 152 |
Process 12 (svchost.exe, PID: 628) | 73 |
Process 13 (svchost.exe, PID: 684) | 329 |
Process 14 (svchost.exe, PID: 780) | 38 |
Process 15 (svchost.exe, PID: 836) | 285 |
Process 16 (svchost.exe, PID: 860) | 664 |
Process 18 (svchost.exe, PID: 264) | 1671 |
Process 19 (spoolsv.exe, PID: 1020) | 22 |
Process 20 (svchost.exe, PID: 1040) | 23 |
Process 21 (taskhost.exe, PID: 1128) | 3 |
Process 23 (explorer.exe, PID: 1244) | 28 |
Process 24 (taskeng.exe, PID: 1268) | 3 |
Process 25 (svchost.exe, PID: 1692) | 24 |
Process 26 (taskeng.exe, PID: 1876) | 5 |
Process 27 (searchindexer.exe, PID: 2032) | 15 |
Process 28 (searchprotocolhost.exe, PID: 1424) | 3 |
Process 31 (mscorsvw.exe, PID: 2128) | 1 |
Process 33 (mscorsvw.exe, PID: 2028) | 108 |
Process 34 (googleupdate.exe, PID: 2220) | 53 |
Process 36 (sppsvc.exe, PID: 248) | 83 |
Process 37 (googleupdate.exe, PID: 1000) | 10 |
Process 38 (googleupdate.exe, PID: 2496) | 10 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 9 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 48 |
Process 41 (googleupdate.exe, PID: 2440) | 10 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x1d0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x8c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880045f6a80, Object_out = 0xfffff8a000c5dc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000c5dc50, ret_val_ptr_out = 0x14 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 97 |
Process 34 (googleupdate.exe, PID: 2220) | 26 |
Process 11 (svchost.exe, PID: 564) | 40 |
Process 36 (sppsvc.exe, PID: 248) | 51 |
Process 37 (googleupdate.exe, PID: 1000) | 10 |
Process 38 (googleupdate.exe, PID: 2496) | 10 |
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 2 |
Process 8 (services.exe, PID: 448) | 26 |
Process 9 (lsass.exe, PID: 464) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 9 |
Process 12 (svchost.exe, PID: 628) | 30 |
Process 13 (svchost.exe, PID: 684) | 10 |
Process 14 (svchost.exe, PID: 780) | 27 |
Process 15 (svchost.exe, PID: 836) | 52 |
Process 16 (svchost.exe, PID: 860) | 222 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 35 |
Process 18 (svchost.exe, PID: 264) | 661 |
Process 20 (svchost.exe, PID: 1040) | 8 |
Process 41 (googleupdate.exe, PID: 2440) | 10 |
Process 23 (explorer.exe, PID: 1244) | 4 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xe1e3b8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3dba20, Length_ptr = 0x10, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
Information | Value |
---|---|
Sequence Length | 23 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
strncpy | _Source = Ultra3, _Count = 0x52, _Dest_out = Ultra3, ret_val_out = Ultra3 |
strncpy | _Source = Ultra3, _Count = 0x52, _Dest_out = Ultra3, ret_val_out = Ultra3 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x364, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880032199e0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007e8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003219780, Object_out = 0xfffff8a001e9fcc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9fcc0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x364, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219960, Object_out = 0xfffff8a001e9fcc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9fcc0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 47 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Process 34 (googleupdate.exe, PID: 2220) | 5 |
Process 36 (sppsvc.exe, PID: 248) | 15 |
Process 37 (googleupdate.exe, PID: 1000) | 3 |
Process 38 (googleupdate.exe, PID: 2496) | 3 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 3 |
Process 8 (services.exe, PID: 448) | 4 |
Process 41 (googleupdate.exe, PID: 2440) | 3 |
Process 13 (svchost.exe, PID: 684) | 2 |
Process 16 (svchost.exe, PID: 860) | 4 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 9 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xe1e358, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x438f80, Length_ptr = 0x26, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\TEMP, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = TEMP, _String2 = $NtUninstallQ923283$, _MaxCount = 0x3, ret_val_out = 80 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 21 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x36c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880032199e0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007e8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003219780, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x36c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219960, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 473 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xe1e4f8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x438f80, Length_ptr = 0x80, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\AppData\Local\Temp, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = ServiceProfiles\NetworkService\AppData\Local\Temp, _String2 = $NtUninstallQ923283$, _MaxCount = 0x30, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = ServiceProfiles\NetworkService\AppData\Local\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2b, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = ServiceProfiles\NetworkService\AppData\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x25, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = ServiceProfiles\NetworkService\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x1d, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\NetworkService\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\ServiceProfiles, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = ServiceProfiles, _String2 = $NtUninstallQ923283$, _MaxCount = 0xe, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = , _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = -36 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 20 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 21 |
Process 34 (googleupdate.exe, PID: 2220) | 8 |
Process 36 (sppsvc.exe, PID: 248) | 18 |
Process 37 (googleupdate.exe, PID: 1000) | 5 |
Process 38 (googleupdate.exe, PID: 2496) | 5 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 5 |
Process 8 (services.exe, PID: 448) | 4 |
Process 41 (googleupdate.exe, PID: 2440) | 5 |
Process 13 (svchost.exe, PID: 684) | 3 |
Process 16 (svchost.exe, PID: 860) | 10 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 9 |
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xe1e218, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x438f80, Length_ptr = 0x1e, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
Information | Value |
---|---|
Sequence Length | 40 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 2 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xe1e250, Length = 0x7c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
_wcsicmp | _Str1 = ServiceProfiles, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
IoAllocateMdl | VirtualAddress_ptr = 0xe1e250, Length = 0x7c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
_wcsicmp | _Str1 = ServiceProfiles, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
Information | Value |
---|---|
Sequence Length | 35 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 22 |
Process 34 (googleupdate.exe, PID: 2220) | 4 |
Process 36 (sppsvc.exe, PID: 248) | 16 |
Process 37 (googleupdate.exe, PID: 1000) | 4 |
Process 38 (googleupdate.exe, PID: 2496) | 4 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 4 |
Process 8 (services.exe, PID: 448) | 9 |
Process 41 (googleupdate.exe, PID: 2440) | 4 |
Process 13 (svchost.exe, PID: 684) | 2 |
Process 16 (svchost.exe, PID: 860) | 9 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 9 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x320, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80018fe510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80018fe510, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 24 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 2 |
Process 33 (mscorsvw.exe, PID: 2028) | 19 |
Process 16 (svchost.exe, PID: 860) | 4 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\ServiceProfiles\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 2 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 37 |
Process 34 (googleupdate.exe, PID: 2220) | 11 |
Process 36 (sppsvc.exe, PID: 248) | 22 |
Process 37 (googleupdate.exe, PID: 1000) | 3 |
Process 38 (googleupdate.exe, PID: 2496) | 3 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 3 |
Process 8 (services.exe, PID: 448) | 2 |
Process 41 (googleupdate.exe, PID: 2440) | 3 |
Process 11 (svchost.exe, PID: 564) | 2 |
Process 12 (svchost.exe, PID: 628) | 71 |
Process 13 (svchost.exe, PID: 684) | 11 |
Process 14 (svchost.exe, PID: 780) | 22 |
Process 15 (svchost.exe, PID: 836) | 26 |
Process 16 (svchost.exe, PID: 860) | 125 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 17 |
Process 18 (svchost.exe, PID: 264) | 292 |
Process 23 (explorer.exe, PID: 1244) | 36 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xe1e7f8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefd728630, Length_ptr = 0x28, Alignment = 0x2 |
Information | Value |
---|---|
Sequence Length | 309 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Process 13 (svchost.exe, PID: 684) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xe1df70, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x438f80, Length_ptr = 0x44, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\system32\sppsvc.exe, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = system32\sppsvc.exe, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = System32\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001a7e670, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001a7e670, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 17 |
Process | Amount |
---|---|
Process 36 (sppsvc.exe, PID: 248) | 1 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Process 8 (services.exe, PID: 448) | 5 |
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\system32\sppsvc.exe, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = system32\sppsvc.exe, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 |
Information | Value |
---|---|
Sequence Length | 14 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Process 36 (sppsvc.exe, PID: 248) | 19 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Process 8 (services.exe, PID: 448) | 4 |
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Process 13 (svchost.exe, PID: 684) | 7 |
Process 16 (svchost.exe, PID: 860) | 4 |
Process 18 (svchost.exe, PID: 264) | 1 |
Process 4 (csrss.exe, PID: 304) | 6 |
Process 27 (searchindexer.exe, PID: 2032) | 36 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 18 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Process 2 (System, PID: 4) | 84 |
Process 36 (sppsvc.exe, PID: 248) | 10 |
Process 8 (services.exe, PID: 448) | 2 |
Process 13 (svchost.exe, PID: 684) | 2 |
Process 18 (svchost.exe, PID: 264) | 1 |
Process 20 (svchost.exe, PID: 1040) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 11 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 3 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 12 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 21 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001ee9470, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
FltpSynchronizedOperationCompletion | ret_val_out = 0xc0000016 |
Information | Value |
---|---|
Sequence Length | 15 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
Information | Value |
---|---|
Sequence Length | 19 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 18 |
Process 4 (csrss.exe, PID: 304) | 1 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x21cf2d8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2ce060, Length_ptr = 0x52, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x130 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002b95b30 |
strncpy | _Source = csrss.exe, _Count = 0x52, _Dest_out = csrss.exe, ret_val_out = csrss.exe |
_strnicmp | _Str1 = csrss.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
_strnicmp | _Str1 = csrss.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x130 |
_wcsnicmp | _String1 = Windows\system32\sppsvc.exe.Config, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = system32\sppsvc.exe.Config, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 6 |
Process 34 (googleupdate.exe, PID: 2220) | 2 |
Process 36 (sppsvc.exe, PID: 248) | 7 |
Process 2 (System, PID: 4) | 7 |
Process 12 (svchost.exe, PID: 628) | 2 |
Process 13 (svchost.exe, PID: 684) | 1 |
Process 15 (svchost.exe, PID: 836) | 120 |
Process 16 (svchost.exe, PID: 860) | 309 |
Process 18 (svchost.exe, PID: 264) | 862 |
Process 19 (spoolsv.exe, PID: 1020) | 22 |
Process 20 (svchost.exe, PID: 1040) | 4 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 18 |
Process | Amount |
---|---|
Process 40 (googlecrashhandler64.exe, PID: 2456) | 5 |
Process 34 (googleupdate.exe, PID: 2220) | 13 |
Process 4 (csrss.exe, PID: 304) | 5 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x741740, Length_ptr = 0x68, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\CRYPTSP.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 |
Information | Value |
---|---|
Sequence Length | 341 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x49e9c0, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\CRYPTSP.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\CRYPTSP.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\SysWOW64\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\SysWOW64\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8002f9d2f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f9d2f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001ef39e0, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
_wcsicmp | _Str1 = SysWOW64, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001ef39e0, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
_wcsicmp | _Str1 = SysWOW64, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8002f9d2f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f9d2f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8002f9d2f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f9d2f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 32 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Process 34 (googleupdate.exe, PID: 2220) | 22 |
Process 36 (sppsvc.exe, PID: 248) | 72 |
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 21 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 4 |
Process 18 (svchost.exe, PID: 264) | 1 |
Process 13 (svchost.exe, PID: 684) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x10 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 21 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 14 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Process 36 (sppsvc.exe, PID: 248) | 17 |
Process 37 (googleupdate.exe, PID: 1000) | 3 |
Process 38 (googleupdate.exe, PID: 2496) | 3 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 3 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 11 |
Process 41 (googleupdate.exe, PID: 2440) | 3 |
Process 13 (svchost.exe, PID: 684) | 2 |
Process 16 (svchost.exe, PID: 860) | 2 |
Process 27 (searchindexer.exe, PID: 2032) | 2 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0xf8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002519060 |
strncpy | _Source = sppsvc.exe, _Count = 0x52, _Dest_out = sppsvc.exe, ret_val_out = sppsvc.exe |
_strnicmp | _Str1 = sppsvc.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = sppsvc.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030f7401 |
IoAllocateMdl | VirtualAddress_ptr = 0xaf3d0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030f7401 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
Information | Value |
---|---|
Sequence Length | 19 |
Process | Amount |
---|---|
Process 36 (sppsvc.exe, PID: 248) | 1 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Process 40 (googlecrashhandler64.exe, PID: 2456) | 1 |
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0xf8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002519060 |
strncpy | _Source = sppsvc.exe, _Count = 0x52, _Dest_out = sppsvc.exe, ret_val_out = sppsvc.exe |
_strnicmp | _Str1 = sppsvc.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = sppsvc.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030f7401 |
IoAllocateMdl | VirtualAddress_ptr = 0xaf450, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030f7401 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0xaf030, Length = 0x408, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030f7401 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
Information | Value |
---|---|
Sequence Length | 4 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 38 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Sequence Length | 7 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 40 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Sequence Length | 488 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x1f0f4b8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3c96a20, Length_ptr = 0x60, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Users\User\AppData\Local\Temp\BITB106.tmp, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Users\User\AppData\Local\Temp\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\User\AppData\Local\Temp\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\User\AppData\Local\Temp\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Users\User\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\User\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\User\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Users\User\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\User\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\User\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Users\User\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\User\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\User\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Users\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Users\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 31 |
Process 11 (svchost.exe, PID: 564) | 2 |
Symbol | Parameters |
---|---|
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8001fbc300 |
Information | Value |
---|---|
Sequence Length | 317 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x49e9c0, Length_ptr = 0x4e, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\RpcRtRemote.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\RpcRtRemote.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x17, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001eedc00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
_wcsicmp | _Str1 = SysWOW64, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001eedc00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
_wcsicmp | _Str1 = SysWOW64, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 79 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x747b1b68, Length_ptr = 0x4a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b55e90, Length_ptr = 0x92, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001a27fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a27fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b55fda, Length_ptr = 0x90, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001a27fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a27fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b55fda, Length_ptr = 0x90, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001a27fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a27fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x23c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003120b50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003120b50, ret_val_ptr_out = 0x3 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 12 |
Process 18 (svchost.exe, PID: 264) | 83 |
Process 36 (sppsvc.exe, PID: 248) | 4 |
Process 34 (googleupdate.exe, PID: 2220) | 2 |
Process 15 (svchost.exe, PID: 836) | 4 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x34be988, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x34be9d0, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
Information | Value |
---|---|
Sequence Length | 13 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 1 |
Process 2 (System, PID: 4) | 119 |
Process 36 (sppsvc.exe, PID: 248) | 1 |
Process 34 (googleupdate.exe, PID: 2220) | 2 |
Process 15 (svchost.exe, PID: 836) | 4 |
Process 16 (svchost.exe, PID: 860) | 12 |
Process 18 (svchost.exe, PID: 264) | 81 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x60c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004486a80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 13 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 60 |
Process 18 (svchost.exe, PID: 264) | 223 |
Process 15 (svchost.exe, PID: 836) | 14 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xba |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x34beb00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004265b00 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004265b00, MemoryDescriptorList_unk = 0xfffffa8002e516c0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb9 |
Information | Value |
---|---|
Sequence Length | 10 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa800283a5f0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa800283a502, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 6 |
Process 18 (svchost.exe, PID: 264) | 19 |
Process 15 (svchost.exe, PID: 836) | 2 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xba |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb9 |
Information | Value |
---|---|
Sequence Length | 42 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189dbf8, Length_ptr = 0x74, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189dbf8, Length_ptr = 0x72, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189dbf8, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e234, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 198 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x747830, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x747830, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x747830, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\system32\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = system32\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189dbc0, Length_ptr = 0x74, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189dbc0, Length_ptr = 0x72, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189dbc0, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e1fc, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x747bc8, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 126 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x747bc8, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x747bc8, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\system32\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = system32\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 114 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7497e0, Length_ptr = 0x8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f308, Length_ptr = 0x28, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f308, Length_ptr = 0xa0, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7497e0, Length_ptr = 0x8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x75884990, Length_ptr = 0x76, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x748bb0, Length_ptr = 0xe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76d0e038, Length_ptr = 0xc, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f3e0, Length_ptr = 0x0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x250, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f428, Length_ptr = 0x0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x254, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f408, Length_ptr = 0x14, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x727b80, Length_ptr = 0x0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f560, Length_ptr = 0x0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76b4277c, Length_ptr = 0xe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76b42c88, Length_ptr = 0x14, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 486 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xae, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76b4277c, Length_ptr = 0xe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76b4277c, Length_ptr = 0xe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x749c58, Length_ptr = 0x8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e314, Length_ptr = 0x28, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e314, Length_ptr = 0xa0, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x749c58, Length_ptr = 0x8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x75884990, Length_ptr = 0x76, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x748c28, Length_ptr = 0xe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76d0e038, Length_ptr = 0xc, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e3ec, Length_ptr = 0x0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e434, Length_ptr = 0x0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x264, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00136efa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00136efa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76b441fc, Length_ptr = 0xc, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e3b4, Length_ptr = 0x76, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76b43308, Length_ptr = 0xe, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f420, Length_ptr = 0x76, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f420, Length_ptr = 0x76, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f374, Length_ptr = 0x88, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xc4, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x749d28, Length_ptr = 0xc, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x749d28, Length_ptr = 0x2a, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd340, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd340, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189f2dc, Length_ptr = 0x94, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x9 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x74a0a0, Length_ptr = 0x72, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\GoogleUpdate.exe, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80031f6701 |
IoAllocateMdl | VirtualAddress_ptr = 0x49e188, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80031f6701 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0x49ea10, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80031f6701 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80031f6701 |
IoAllocateMdl | VirtualAddress_ptr = 0x189f388, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80031f6701 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a000d29780, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d29780, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 32 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x751260, Length_ptr = 0x62, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 60 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xfde268, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0x9a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x280, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a00136efa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00136efa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xfde268, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0x8e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x280, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a00136efa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00136efa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030dd501 |
IoAllocateMdl | VirtualAddress_ptr = 0xfde2d8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030dd501 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfdeb60, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030dd501 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030dd501 |
IoAllocateMdl | VirtualAddress_ptr = 0x16ff578, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030dd501 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x290, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x13 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 4 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2e000 |
PsGetCurrentThreadId | ret_val_unk_out = 0x9c8 |
Information | Value |
---|---|
Sequence Length | 9 |
Process | Amount |
---|---|
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002b1dec0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 459 |
Process | Amount |
---|---|
Process 11 (svchost.exe, PID: 564) | 2 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#FDC#GENERIC_FLOPPY_DRIVE#5&e9e2334&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#IDE#CdRomHL-DT-ST_DVD-ROM_GDR-T10N_______________1.05____#5&23a61b21&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#IDE#CdRomHL-DT-ST_DVD-ROM_GDR-T10N_______________1.05____#5&28836b88&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.2.____#5&2770a7af&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.2.____#5&2770a7af&0&0.1.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.2.____#5&3a2a5854&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.3.____#5&2770a7af&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.4.____#5&2770a7af&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.4.____#5&2770a7af&0&0.1.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{1181b660-d211-11e4-b006-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{1181b660-d211-11e4-b006-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#0000000000007E00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#000000046528EC00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#0000001E628B7200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#00000020D3A1E800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#00000020F3026800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#000000211262E800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#0000002131C36800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#0000000000007E00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#000000075343E000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#0000001E628B7200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#00000020D3A1E800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#00000020F3026800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#000000211262E800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#0000002131C36800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{fb2b09e0-bdf0-11e4-97d2-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#Volume#{fb2b09e0-bdf0-11e4-97d2-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT1#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT10#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT11#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT12#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT13#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT14#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT15#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT16#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT2#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT3#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT4#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT5#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT6#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT7#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT8#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT9#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 39 |
Process | Amount |
---|---|
Process 11 (svchost.exe, PID: 564) | 43 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 12 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 51 |
Process 34 (googleupdate.exe, PID: 2220) | 4 |
Process 11 (svchost.exe, PID: 564) | 89 |
Process 13 (svchost.exe, PID: 684) | 8 |
Process 14 (svchost.exe, PID: 780) | 438 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 49 |
Process | Amount |
---|---|
Process 11 (svchost.exe, PID: 564) | 2 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x234 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Control, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 96 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x224, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa800326b260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800326b260, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x218, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8002e031b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e031b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x204, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a000dbf3c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000dbf3c0, ret_val_ptr_out = 0x25 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76401ab8, Length_ptr = 0x7e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76401a90, Length_ptr = 0x24, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x764019a0, Length_ptr = 0x3c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x764019a0, Length_ptr = 0x3c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x224, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x290, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003162da0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003162da0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x294, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa80030dcd40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030dcd40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa80031f6700, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031f6700, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003124b10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003124b10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 60 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwSetEvent | EventHandle_unk = 0xffffffff800006d8, PreviousState_ptr_out = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c200 |
strncpy | _Source = system, _Count = 0x52, _Dest_out = system, ret_val_out = system |
_snprintf | _Count = 0x52, _Format = %s#2, _Dest_out = system#2, ret_val_out = 8 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
Information | Value |
---|---|
Sequence Length | 44 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x8ebb0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x8bc400, Length_ptr = 0x12, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002e2ada8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002e2ada8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002e2ada8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002e2ada8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
Information | Value |
---|---|
Sequence Length | 11085 |
Process | Amount |
---|---|
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d7d0, Object_out = 0xfffff8a003e4c7f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003e4c7f0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d400, Object_out = 0xfffff8a001e55520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e55520, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d280, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0xa | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x20040, Length_ptr = 0x50, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x20040, Length_ptr = 0xe, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b59dd2, Length_ptr = 0x86, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b59548, Length_ptr = 0x7e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b593c8, Length_ptr = 0x84, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800464d380, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x5c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800464d388, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800464d408, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = en-US, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d030, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff800007f8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d120, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000ebc801, Object_ptr_out = 0xfffff8800464d380, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x38e630, Length_ptr = 0xa, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800464d380, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5a740, Length_ptr = 0xa0, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0x8c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x433558, Length_ptr = 0x2e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5a9ce, Length_ptr = 0x78, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b597f4, Length_ptr = 0xaa, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0x8c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x7 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x433578, Length_ptr = 0x2e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5aa48, Length_ptr = 0x56, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0x8c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x6 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x433598, Length_ptr = 0x2e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b594ec, Length_ptr = 0x2a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0x8c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x5 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4335e0, Length_ptr = 0x2e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b59244, Length_ptr = 0x3e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a7e6c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a7e6c0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0xa4, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001efa800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7efe1440, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7588a364, Length_ptr = 0x3a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0xc6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x435250, Length_ptr = 0x12, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a003f80950, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f80950, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0x68, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0x68, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x38ed08, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0x78, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x435730, Length_ptr = 0x34, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x38f128, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x7c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001efa800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x76b64738, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0x8e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0xc6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x38f1d0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x76b64738, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x435970, Length_ptr = 0x34, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Program Files (x86), _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0xc8, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0xc8, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x434e78, Length_ptr = 0x6a, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0xc6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x434f00, Length_ptr = 0x7c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4359a0, Length_ptr = 0x7c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4359a0, Length_ptr = 0x7c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a44480, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a44480, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x38f3d0, Length_ptr = 0x18, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a000beffc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000beffc0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x38f3d0, Length_ptr = 0x18, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4359a0, Length_ptr = 0x6a, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\IPHLPAPI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\IPHLPAPI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a44480, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a44480, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x38f030, Length_ptr = 0xe, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a000be7eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000be7eb0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x38f030, Length_ptr = 0x14, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x435da0, Length_ptr = 0x66, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x44, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\WINNSI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x44, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\WINNSI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a44480, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a44480, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x38f3d0, Length_ptr = 0x18, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x435da0, Length_ptr = 0x6a, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 186 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\System32\drivers\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\System32\drivers\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004682720, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004682720, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001f3ec00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001f3ec00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004682720, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004682720, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Sequence Length | 4428 |
Process | Amount |
---|---|
Process 14 (svchost.exe, PID: 780) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x37c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff88002ad6950, Object_out = 0xfffff8a001b806b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b806b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x37c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88002ad6958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007b0, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff88002ad69d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = .NET CLR Data, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = .NET CLR Networking, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = .NET CLR Networking 4.0.0.0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = .NET Data Provider for Oracle, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = .NET Data Provider for SqlServer, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = .NET Memory Cache 4.0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = .NETFramework, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 1394ohci, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ACPI, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AcpiPmi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = adp94xx, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = adpahci, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = adpu320, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = adsi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AeLookupSvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AFD, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = agp440, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ALG, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = aliide, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = amdide, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AmdK8, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AmdPPM, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = amdsata, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = amdsbs, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = amdxata, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AppID, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AppIDSvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Appinfo, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x1c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AppMgmt, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = arc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = arcsas, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ASP.NET, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ASP.NET_4.0.30319, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = aspnet_state, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AsyncMac, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = atapi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AudioEndpointBuilder, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AudioSrv, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AxInstSV, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = b06bdrv, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = b57nd60a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BattC, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BDESVC, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x2b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Beep, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x2c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BFE, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x2d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BITS, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x2e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = blbdrive, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x2f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = bowser, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x30, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BrFiltLo, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x31, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BrFiltUp, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x32, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Browser, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x33, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Brserid, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x34, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BrSerWdm, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x35, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BrUsbMdm, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x36, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BrUsbSer, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x37, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BTHMODEM, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x38, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BTHPORT, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x39, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = bthserv, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x3a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = cdfs, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x3b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = cdrom, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x3c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CertPropSvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x3d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = circlass, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x3e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CLFS, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x3f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = clr_optimization_v2.0.50727_32, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x40, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = clr_optimization_v2.0.50727_64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x41, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = clr_optimization_v4.0.30319_32, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x42, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = clr_optimization_v4.0.30319_64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x43, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CmBatt, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x44, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = cmdide, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x45, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CNG, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x46, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Compbatt, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x47, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CompositeBus, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x48, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = COMSysApp, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x49, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = crcdisk, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x4a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = crypt32, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x4b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CryptSvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x4c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CSC, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x4d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CscService, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x4e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = DCLocator, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x4f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = DcomLaunch, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x50, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = defragsvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x51, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = DfsC, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x52, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Dhcp, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x53, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = discache, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x54, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Disk, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x55, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = dmvsc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x56, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Dnscache, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x57, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = dot3svc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x58, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = DPS, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x59, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = DXGKrnl, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x5a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = EapHost, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x5b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ebdrv, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x5c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = EFS, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x5d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehRecvr, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x5e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehSched, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x5f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = elxstor, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x60, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ErrDev, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b0, Index = 0x61, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 25 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 4 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x224, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880045ada80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 12 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x141eab0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x749bf8, Length_ptr = 0xe2, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
Information | Value |
---|---|
Sequence Length | 9 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 2 |
Process 2 (System, PID: 4) | 1 |
Process 14 (svchost.exe, PID: 780) | 4 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 55 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 4 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880045ad340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 95 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002ff7530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002ff7530, ret_val_ptr_out = 0x3 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xfde268, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16ff754, Length_ptr = 0x94, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8003285410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003285410, ret_val_ptr_out = 0x3 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xfde268, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16ff754, Length_ptr = 0x94, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x74a3f0, Length_ptr = 0x2a, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 4 |
Symbol | Parameters |
---|---|
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65b00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffffa80018b0200, Object_ptr_out = 0xfffff88004683400, Object_out = 0xfffff8a001a44460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a44460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 8 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Sequence Length | 21 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004683430, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 4 |
Symbol | Parameters |
---|---|
_wcsnicmp | _String1 = fastfat, _String2 = netbt, _MaxCount = 0x7, ret_val_out = -8 |
_wcsnicmp | _String1 = fastfat, _String2 = afd, _MaxCount = 0x7, ret_val_out = 5 |
_wcsnicmp | _String1 = fastfat, _String2 = Null, _MaxCount = 0x7, ret_val_out = -8 |
_wcsnicmp | _String1 = fastfat, _String2 = Beep, _MaxCount = 0x7, ret_val_out = 4 |
_wcsnicmp | _String1 = fastfat, _String2 = tcpip, _MaxCount = 0x7, ret_val_out = -14 |
_wcsnicmp | _String1 = fastfat, _String2 = Nsiproxy, _MaxCount = 0x7, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 118 |
Process | Amount |
---|---|
Process 13 (svchost.exe, PID: 684) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff88002a60950, Object_out = 0xfffff8a000d277f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d277f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0xe0, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88002a60958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007b8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd2650, ResultLength_ptr_out = 0xfffff88002a609d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Application, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = HardwareEvents, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -13 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b8, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Internet Explorer, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -12 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b8, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Key Management Service, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -10 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b8, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Media Center, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b8, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Security, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b8, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007b8, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002e08a70 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Windows PowerShell, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a60600, Object_out = 0xfffff8a000d277f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d277f0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007b8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a606f0, Object_out = 0xfffff8a000d277f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d277f0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff88002a60950, Object_out = 0xfffff8a000d277f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d277f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 17 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 10 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003d64200, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003d64200, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 14 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 11 |
Process 6 (csrss.exe, PID: 364) | 2 |
Symbol | Parameters |
---|---|
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x59c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xffffeb9000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88003d64a28, ret_val_unk_out = 0x0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003d64a20, Object_out = 0xfffffa80030b5c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030b5c80, ret_val_ptr_out = 0x2 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003d647a0, Object_out = 0xfffffa80030b5c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030b5c80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 61 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x20, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880044599e0, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = {430FD4D0-B729-4F61-AA34-91526481799D}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 38 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = {4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 38 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = {8A69D345-D564-463C-AFF1-A69D9E530F96}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 38 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = {FDA71E6F-AC4C-4A00-8B70-9958A68906BF}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 38 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004459780, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459960, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 343 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f1321f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001e9fe0f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f1321f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001e9fe0f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001e9fe0f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001eed7df, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a00030493f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa80030d8ee0, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001eda8af, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001a8e02f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a00181ee0f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a0016a11bf, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa80030d8ee0, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001ef325f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa80030d8ee0, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9 |
_snwprintf | _Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6 |
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
RtlNtStatusToDosError | Status_unk = 0xc0000022, ret_val_out = 0x5 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1fc |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000 |
Information | Value |
---|---|
Sequence Length | 9 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x8ebb0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x8bc400, Length_ptr = 0x1e, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
Information | Value |
---|---|
Sequence Length | 13 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x8ebb0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x18f3e0, Length_ptr = 0x10, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002bb4310, PriorityBoost = 0 |
Information | Value |
---|---|
Sequence Length | 7 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 |
Information | Value |
---|---|
Sequence Length | 19 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 6 |
Symbol | Parameters |
---|---|
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x108, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffffa8000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800447fa28, ret_val_unk_out = 0x0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800447fa20, Object_out = 0xfffffa8003156f20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003156f20, ret_val_ptr_out = 0x2 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0xb0c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800447f7a0, Object_out = 0xfffffa8003156f20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003156f20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8003227378, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8003227378, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 8 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 6 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8003227378, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8003227378, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 21 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 103 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 15 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Process 36 (sppsvc.exe, PID: 248) | 8 |
Process 13 (svchost.exe, PID: 684) | 5 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 322 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed78, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3373b0, Length_ptr = 0x98, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows\Microsoft.NET\Framework64\v4.0.30319\ngenofflinequeuelock.dat, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = Microsoft.NET\Framework64\v4.0.30319\ngenofflinequeuelock.dat, _String2 = $NtUninstallQ923283$, _MaxCount = 0x3c, ret_val_out = 73 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows\Microsoft.NET\Framework64\v4.0.30319, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = Microsoft.NET\Framework64\v4.0.30319, _String2 = $NtUninstallQ923283$, _MaxCount = 0x23, ret_val_out = 73 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows\Microsoft.NET\Framework64, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = Microsoft.NET\Framework64, _String2 = $NtUninstallQ923283$, _MaxCount = 0x18, ret_val_out = 73 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows\Microsoft.NET, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = Microsoft.NET, _String2 = $NtUninstallQ923283$, _MaxCount = 0xc, ret_val_out = 73 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = , _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = -36 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 5 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Process 18 (svchost.exe, PID: 264) | 29 |
Process 13 (svchost.exe, PID: 684) | 1 |
Process 14 (svchost.exe, PID: 780) | 1 |
Process 15 (svchost.exe, PID: 836) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcae568, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xcaec08, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa800328b701 |
ProbeForRead | Address_ptr = 0xcae638, Length_ptr = 0x4, Alignment = 0x1 |
Information | Value |
---|---|
Sequence Length | 38 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 3268 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Accessibility, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AspNetMMCExt, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AuditPolicyGPManagedStubs.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BDATunePIA, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/ComSvcConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/dfsvc.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/MSBuild.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/SMSvcHost.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/WsatConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ComSvcConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CustomMarshalers, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CustomMarshalers, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = dfsvc, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehCIR, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehexthost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiActivScp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiBmlDataCarousel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiExtens, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiiTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiProxy, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiTVMSMusic, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiUPnP, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiUserXp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiVidCtl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiwmp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiWUapi, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehRecObj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehshell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = EventViewer, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = loadmxf, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 23 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcepg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = MCESidebarCtrl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcglidhostobj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcplayerinterop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcstore, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcstoredb, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcupdate, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Mcx2Dvcs, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Activities.Build, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.ApplicationId.Framework, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.ApplicationId.RuleWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Conversion.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Engine, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Engine, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Framework, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Framework, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x30, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x31, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Tasks.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x32, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Utilities, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x33, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Utilities.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x34, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.CSharp, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x35, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.GroupPolicy.AdmTmplEditor, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x36, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.GroupPolicy.Interop, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x37, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.GroupPolicy.Reporting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x38, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Ink, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x39, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Internal.Tasks.Dataflow, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.ManagementConsole, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Bml, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.iTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.iTv.Hosting, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x40, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.iTV.Media, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x41, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.ITVVM, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x42, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Mheg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x43, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Playback, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x44, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Shell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x45, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Sports, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x46, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.TV.Tuners.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x47, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.UI, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x48, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Diagnostics, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x49, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x4a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Utility, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x4b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.ConsoleHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x4c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Editor, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x4d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.GPowerShell, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x4e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.GraphicalHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x4f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Security, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x50, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x51, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x52, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x53, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x54, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x55, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x56, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x57, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Transactions.Bridge, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x58, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Transactions.Bridge.Dtc, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x59, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Transactions.Bridge.Dtc, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x5a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x5b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x5c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic.Activities.Compiler, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x5d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic.Compatibility, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x5e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic.Compatibility.Data, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x5f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualC, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x60, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualC, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x61, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 58 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 17 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f186d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 2 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 7 |
Process 2 (System, PID: 4) | 4 |
Process 20 (svchost.exe, PID: 1040) | 1 |
Process 26 (taskeng.exe, PID: 1876) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x660 |
Information | Value |
---|---|
Sequence Length | 607 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x528, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0x1a8f078, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x594, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0x1a8f078, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x594, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0x1a8e528, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1ec29c0, Length_ptr = 0x10, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x594, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002f2bc40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f2bc40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8dde0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefa873270, Length_ptr = 0x1c, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x594, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002f2bc40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f2bc40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8f058, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb6 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb5 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb6 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000b8cb60 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b8cb60, MemoryDescriptorList_unk = 0xfffffa8002f7e130 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 |
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb5 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb1e00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb1e00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 124 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 14 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x30e6d0, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 212 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 15 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35b6c0, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35b880, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 248 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 15 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35ba40, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35bc00, Length_ptr = 0xd6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 124 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 53 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35bf80, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 93 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35c140, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 96 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35c4c0, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 98 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35c840, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 114 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 5 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35cae0, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 36 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 18 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 88 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 22 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37abc0, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 160 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 10 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38acb0, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 113 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38af50, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 91 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38b810, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 96 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3aac80, Length_ptr = 0x130, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 34 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 719 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3d9230, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3d9430, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3d9630, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3d9830, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37baa0, Length_ptr = 0xfa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f187d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3e71f0, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 136 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37bcc0, Length_ptr = 0x106, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
Information | Value |
---|---|
Sequence Length | 127 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37bee0, Length_ptr = 0xfa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f23bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f23bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37c100, Length_ptr = 0xfc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 25 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Process 20 (svchost.exe, PID: 1040) | 13 |
Symbol | Parameters |
---|---|
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x41c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88002a96a28, ret_val_unk_out = 0x0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a96a20, Object_out = 0xfffffa8002ff56d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002ff56d0, ret_val_ptr_out = 0x4 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a967a0, Object_out = 0xfffffa8002ff56d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002ff56d0, ret_val_ptr_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 261 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3a5cb0, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f237d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f43501, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf5a7d0, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 195 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3d9a30, Length_ptr = 0xf4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 33 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 189 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3da430, Length_ptr = 0xf4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf7e890, Length_ptr = 0xfc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
Information | Value |
---|---|
Sequence Length | 19 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 105 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf71e80, Length_ptr = 0x108, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 63 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3dac30, Length_ptr = 0xf4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
Information | Value |
---|---|
Sequence Length | 52 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf7ede0, Length_ptr = 0xfe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 184 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc1d80, Length_ptr = 0x152, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 136 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf7b820, Length_ptr = 0x13c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 16 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf7bac0, Length_ptr = 0x138, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 176 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc4750, Length_ptr = 0x134, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f233b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f233b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 85 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfdf660, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 282 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xff43a0, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3dae30, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 35 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 95 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc2d90, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 243 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc2f70, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 25 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc1d50, Length_ptr = 0x120, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 23 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 136 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc49d0, Length_ptr = 0x128, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 52 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc4ed0, Length_ptr = 0x12a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 48 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 121 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3dc430, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 38 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 4 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3dc630, Length_ptr = 0xec, Alignment = 0x2 |
Information | Value |
---|---|
Sequence Length | 127 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfe07e0, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
Information | Value |
---|---|
Sequence Length | 11 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002e58650 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002e58602, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 226 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfe0d20, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xff6860, Length_ptr = 0x96, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 57 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1007800, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 248 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 9 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3dc830, Length_ptr = 0xea, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x10371f0, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 286 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc4050, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1047a50, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 56 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 26 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 43 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1045860, Length_ptr = 0xc6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 377 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1045ba0, Length_ptr = 0xc4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1007e20, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144c420, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 8 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x448 |
Information | Value |
---|---|
Sequence Length | 226 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1046220, Length_ptr = 0xba, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x10463c0, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 167 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xff74c0, Length_ptr = 0xf8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
Information | Value |
---|---|
Sequence Length | 168 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144c720, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 10 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 5 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 134 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 7 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1466500, Length_ptr = 0xba, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 271 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14758b0, Length_ptr = 0xa2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x104dad0, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 408 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x104df80, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1478350, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x10087c0, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 464 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1008de0, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1471940, Length_ptr = 0x92, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x148bdb0, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1008fa0, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 540 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14a9600, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14ab930, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd43b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14a98a0, Length_ptr = 0xd6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1499d00, Length_ptr = 0x9e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 446 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144cf20, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14b04e0, Length_ptr = 0xb0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce87d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14a9d00, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 258 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x104e610, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf72540, Length_ptr = 0x108, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 168 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14aa080, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 426 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14b0d20, Length_ptr = 0xae, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144d120, Length_ptr = 0xf6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14ac7d0, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 70 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14aa320, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 138 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14cd980, Length_ptr = 0x9c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f187d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f187d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 107 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 5 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xff7d40, Length_ptr = 0xf8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001228010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 117 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14ad190, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 39 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 46 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 113 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14e2020, Length_ptr = 0xb8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001504010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 224 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14fc480, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0013cf010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bcb401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144d520, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 130 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14de6f0, Length_ptr = 0xb6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 332 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x150dfa0, Length_ptr = 0xae, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144d720, Length_ptr = 0xf4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce83b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1511b20, Length_ptr = 0xbc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
Information | Value |
---|---|
Sequence Length | 37 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
Information | Value |
---|---|
Sequence Length | 151 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1527f20, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 382 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1528600, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144db20, Length_ptr = 0xee, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15106a0, Length_ptr = 0xb6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 38 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 436 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf72780, Length_ptr = 0x112, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14d9c40, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xff8180, Length_ptr = 0x102, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 648 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14d9f10, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1528fa0, Length_ptr = 0xa2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144dd20, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14cac20, Length_ptr = 0xb0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1529470, Length_ptr = 0xa2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 284 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 4 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144df20, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15128f0, Length_ptr = 0xb8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 372 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xff83a0, Length_ptr = 0xfa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15490a0, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f007d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f007d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15493e0, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 216 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15437e0, Length_ptr = 0xb0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15497f0, Length_ptr = 0xc6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 121 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14def70, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 144 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1560030, Length_ptr = 0xde, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 312 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x155da40, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ce8201, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14df4b0, Length_ptr = 0xd2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 224 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x155e750, Length_ptr = 0x9a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 375 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x155f0f0, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15603f0, Length_ptr = 0xde, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x155fa90, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 191 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1575fe0, Length_ptr = 0xb4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144e520, Length_ptr = 0xf6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 302 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x157d1b0, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001228010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf729c0, Length_ptr = 0x116, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
Information | Value |
---|---|
Sequence Length | 336 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x158a450, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1561020, Length_ptr = 0xe4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a79010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a79010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1577d20, Length_ptr = 0xac, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 825 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a0040, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a0520, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001504010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0013cf401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a0930, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a0c70, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a1080, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a1220, Length_ptr = 0xbc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14dfc90, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
Information | Value |
---|---|
Sequence Length | 400 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a3740, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15615c0, Length_ptr = 0xe6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x157ade0, Length_ptr = 0xac, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 496 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144eb20, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15d1b60, Length_ptr = 0xb4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15481b0, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1548350, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 90 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1561a70, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
Information | Value |
---|---|
Sequence Length | 372 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144ef20, Length_ptr = 0xee, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15d6ea0, Length_ptr = 0xb6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144f120, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 108 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15d80a0, Length_ptr = 0xb0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 15 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 139 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160f100, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 2680 |
Process | Amount |
---|---|
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b07d0, Object_out = 0xfffff8a003e4c7f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003e4c7f0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b0400, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b0280, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0xa | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x20040, Length_ptr = 0x50, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x20040, Length_ptr = 0xe, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b59dd2, Length_ptr = 0x86, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b59548, Length_ptr = 0x7e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b593c8, Length_ptr = 0x84, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff880046b0380, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x5c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880046b0388, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff880046b0408, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = en-US, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b0030, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b0120, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff880046b0380, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3de8b0, Length_ptr = 0xa, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff880046b0380, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5a740, Length_ptr = 0xa0, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0x8c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x8 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x793558, Length_ptr = 0x2e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5a9ce, Length_ptr = 0x78, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b597f4, Length_ptr = 0xaa, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0x8c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x7 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x793578, Length_ptr = 0x2e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5aa48, Length_ptr = 0x56, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0x8c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x6 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x793598, Length_ptr = 0x2e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b594ec, Length_ptr = 0x2a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0x8c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x5 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7935e0, Length_ptr = 0x2e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b59244, Length_ptr = 0x3e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001f296d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f296d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0xa4, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a0013ca300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca300, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7efe1440, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7588a364, Length_ptr = 0x3a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0xc6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x795250, Length_ptr = 0x12, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a003f80950, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f80950, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0x68, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0x68, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b42001 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27e028, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b42001 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27e8b0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b42001 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b42001 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x3def84, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b42001 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0x78, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x795730, Length_ptr = 0x34, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3df3a4, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x7c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a0013ca300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca300, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x76b64738, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0x8e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0xc6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3df44c, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x76b64738, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x795970, Length_ptr = 0x34, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Program Files (x86), _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0xc8, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0xc8, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x794e78, Length_ptr = 0x6a, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5738d8, Length_ptr = 0xc6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x794f00, Length_ptr = 0x7c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7959a0, Length_ptr = 0x7c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7959a0, Length_ptr = 0x7c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001a0f1c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a0f1c0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3df64c, Length_ptr = 0x18, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a000beffc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000beffc0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3df64c, Length_ptr = 0x18, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7959a0, Length_ptr = 0x6a, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e860, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\IPHLPAPI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e860, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\IPHLPAPI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001a0f1c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a0f1c0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3df2ac, Length_ptr = 0xe, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a000be7eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000be7eb0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3df2ac, Length_ptr = 0x14, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x795da0, Length_ptr = 0x66, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e860, Length_ptr = 0x44, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\WINNSI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e860, Length_ptr = 0x44, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\WINNSI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001a0f1c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a0f1c0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3df64c, Length_ptr = 0x18, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x795da0, Length_ptr = 0x6a, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e860, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e860, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80030b0060 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x9c0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 19 |
Process | Amount |
---|---|
Process 40 (googlecrashhandler64.exe, PID: 2456) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x1aefa8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x322900, Length_ptr = 0x64, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x998 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800309b060 |
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x998 |
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x998 |
Information | Value |
---|---|
Sequence Length | 121 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65b00 |
_snwprintf | _Count = 0x52, _Format = %S, _Dest_out = Ultra3, ret_val_out = 6 |
_snwprintf | _Count = 0x52, _Format = %S, _Dest_out = Ultra3, ret_val_out = 6 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
Information | Value |
---|---|
Sequence Length | 2 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 30 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65b00 |
Information | Value |
---|---|
Sequence Length | 73 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160f510, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 263 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160c320, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1613100, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 127 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1621ff0, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 48 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160c7d0, Length_ptr = 0xe6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 373 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1614180, Length_ptr = 0xae, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a7930, Length_ptr = 0xd2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 185 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144f720, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1623030, Length_ptr = 0xba, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 121 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144fb20, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcb010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 309 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x162eed0, Length_ptr = 0x9c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1618980, Length_ptr = 0xac, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a81f0, Length_ptr = 0xd2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa97d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 25 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
Information | Value |
---|---|
Sequence Length | 256 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160d040, Length_ptr = 0xdc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x162f7c0, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 180 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1619280, Length_ptr = 0xb6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 380 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160d220, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160d4f0, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1660530, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 98 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1610930, Length_ptr = 0xfc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 361 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160d6d0, Length_ptr = 0xe6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1661a30, Length_ptr = 0xae, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 224 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160d8b0, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1662030, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 144 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1632470, Length_ptr = 0x9c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 38 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144fd20, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 149 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1663170, Length_ptr = 0xb4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 234 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x13c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001559950, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001559950, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x128, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa8003102090, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003102090, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaeec8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaeec8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x128, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaf3d0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7feff2a5830, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa8002c21ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002c21ea0, ret_val_ptr_out = 0x3 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a114d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a114d0, ret_val_ptr_out = 0xe |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0xcaec98, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3611c0, Length_ptr = 0x92, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat, _String2 = $NtUninstallQ923283$, _MaxCount = 0x39, ret_val_out = 73 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows\Microsoft.NET\Framework64\v4.0.30319, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = Microsoft.NET\Framework64\v4.0.30319, _String2 = $NtUninstallQ923283$, _MaxCount = 0x23, ret_val_out = 73 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows\Microsoft.NET\Framework64, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = Microsoft.NET\Framework64, _String2 = $NtUninstallQ923283$, _MaxCount = 0x18, ret_val_out = 73 |
Information | Value |
---|---|
Sequence Length | 409 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows\Microsoft.NET, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = Microsoft.NET, _String2 = $NtUninstallQ923283$, _MaxCount = 0xc, ret_val_out = 73 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
_wcsnicmp | _String1 = Windows, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = , _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = -36 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaeb08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xcaf188, Length_ptr = 0x56, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa800328b701 |
ProbeForRead | Address_ptr = 0xcaebd8, Length_ptr = 0x4, Alignment = 0x1 |
ProbeForRead | Address_ptr = 0xcaed18, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaed18, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaefb8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xcaf418, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Accessibility, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = AspNetMMCExt, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = AuditPolicyGPManagedStubs.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = BDATunePIA, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/ComSvcConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/dfsvc.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/MSBuild.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/SMSvcHost.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/WsatConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ComSvcConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = CustomMarshalers, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = CustomMarshalers, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = dfsvc, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehCIR, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 428 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehshell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = EventViewer, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = loadmxf, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 23 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mcepg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MCESidebarCtrl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mcglidhostobj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mcplayerinterop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mcstore, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mcstoredb, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mcupdate, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Mcx2Dvcs, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Activities.Build, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.ApplicationId.Framework, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.ApplicationId.RuleWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Conversion.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Engine, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Engine, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Framework, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Framework, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x30, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x31, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Tasks.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x32, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Utilities, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x33, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Build.Utilities.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x34, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.CSharp, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x35, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.GroupPolicy.AdmTmplEditor, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x36, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.GroupPolicy.Interop, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x37, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.GroupPolicy.Reporting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x38, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Ink, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x39, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Internal.Tasks.Dataflow, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.ManagementConsole, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.Bml, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.iTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.iTv.Hosting, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x40, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.iTV.Media, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x41, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.ITVVM, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x42, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.Mheg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x43, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.Playback, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x44, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.Shell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x45, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.Sports, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x46, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 315 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Entity.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Entity.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Linq, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Linq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.OracleClient, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.OracleClient, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Services, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Services.Client, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Services.Client, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xb9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Services.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xba, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Services.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xbb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.SqlXml, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xbc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.SqlXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xbd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Deployment, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xbe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Deployment, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xbf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Design, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Device, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.DirectoryServices, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.DirectoryServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.DirectoryServices.AccountManagement, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.DirectoryServices.AccountManagement, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.DirectoryServices.Protocols, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.DirectoryServices.Protocols, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Drawing, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xc9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xca, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Drawing.Design, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xcb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Drawing.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xcc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Dynamic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xcd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.EnterpriseServices, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xce, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 448 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Runtime.Caching, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Runtime.DurableInstancing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Runtime.Remoting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Runtime.Remoting, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xea, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Runtime.Serialization, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xeb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Runtime.Serialization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xec, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Runtime.Serialization.Formatters.Soap, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xed, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Runtime.Serialization.Formatters.Soap, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xee, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Security, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xef, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Security, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.Activation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.Channels, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.Discovery, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.Internals, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.Routing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.ServiceMoniker40, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xf9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.Web, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xfa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceModel.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xfb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceProcess, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xfc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ServiceProcess, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xfd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Speech, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xfe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Speech, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xff, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Transactions, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x100, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Transactions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x101, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x102, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x103, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Abstractions, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x104, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Abstractions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x105, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.ApplicationServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x106, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.DataVisualization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x107, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.DataVisualization.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x108, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.DynamicData, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x109, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.DynamicData, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x10a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.DynamicData.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x10b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.DynamicData.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x10c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Entity, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x10d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Entity, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x10e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Entity.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x10f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Entity.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x110, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Extensions, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x111, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Extensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x112, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 197 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x34b850, Length_ptr = 0x102, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x33b270, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 213 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1686530, Length_ptr = 0x80, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32f3d0, Length_ptr = 0x72, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
Information | Value |
---|---|
Sequence Length | 58 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x33bcf0, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 136 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x33beb0, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 344 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x33c770, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00135c401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x33c930, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x33caf0, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 44 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfd29d0, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 5 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 11 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 4 |
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x814, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffffa8000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88003ee7a28, ret_val_unk_out = 0x0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee7a20, Object_out = 0xfffffa80030bfea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030bfea0, ret_val_ptr_out = 0x8 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee77a0, Object_out = 0xfffffa80030bfea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030bfea0, ret_val_ptr_out = 0x8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 141 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x368530, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x368730, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 29 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000774, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002775310, Object_out = 0xfffffa8002b06cd0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002b06cd0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000770, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002775310, Object_out = 0xfffffa8002e47050, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e47050, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 10 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000660, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046197e0, Object_out = 0xfffffa800326d870, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800326d870, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 12 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Process 18 (svchost.exe, PID: 264) | 1 |
Process 19 (spoolsv.exe, PID: 1020) | 1 |
Process 36 (sppsvc.exe, PID: 248) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8003145900 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0xfffffa8002865602, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 498 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcaac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bcaac0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcbac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bcbac0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bccac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bccac0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcdac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bcdac0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcead0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bcead0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcfad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bcfad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd0ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd0ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd1ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd1ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd2ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd2ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd3ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd3ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd4ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd4ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd5ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd5ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd6ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd6ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd7ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd7ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd8ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd8ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd9ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bd9ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8ebc8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
Information | Value |
---|---|
Sequence Length | 1124 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
ProbeForRead | Address_ptr = 0x1a8ea28, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b0090, Length_ptr = 0x5e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004257d00 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004257d00, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004258d00 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004258d00, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004259d00 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004259d00, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800425ad00 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff8800425ad00, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007ef4b60 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007ef4b60, MemoryDescriptorList_unk = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f1dac0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f1dac0, MemoryDescriptorList_unk = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f1eac0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f1eac0, MemoryDescriptorList_unk = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f1fac0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f1fac0, MemoryDescriptorList_unk = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f20ac0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f20ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f21ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f21ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f22ad0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 185 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x396980, Length_ptr = 0x10e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x369f30, Length_ptr = 0xee, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 35 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x15c |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 99 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x356eb0, Length_ptr = 0x102, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
Information | Value |
---|---|
Sequence Length | 174 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x154b2a0, Length_ptr = 0x138, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 224 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x384590, Length_ptr = 0x134, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf67a40, Length_ptr = 0x14a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 134 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x153e270, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 260 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x155faa0, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x36a330, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cebbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 42 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf73c20, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 121 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 439 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1681670, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf73e00, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cedbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1560a60, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf73fe0, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 221 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf6cc90, Length_ptr = 0x120, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 133 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x384810, Length_ptr = 0x128, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 105 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x384a90, Length_ptr = 0x12e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 119 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x384d10, Length_ptr = 0x12a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 296 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3973a0, Length_ptr = 0x108, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15553c0, Length_ptr = 0x102, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 32 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 143 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 3 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1658320, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdcbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdcbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 121 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16584e0, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 425 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16586a0, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1658860, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1003140, Length_ptr = 0x96, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1658a20, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 313 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1658be0, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1658da0, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1658f60, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 186 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1659120, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 411 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f4e30, Length_ptr = 0xea, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1001d20, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f5030, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf750c0, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 345 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f0220, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f5230, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 220 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f5430, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 193 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3d44b0, Length_ptr = 0xc4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1659740, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 169 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f5730, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18450, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 312 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3d5350, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001cda301, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f5a30, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 208 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3ed8b0, Length_ptr = 0xa2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1503a60, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
Information | Value |
---|---|
Sequence Length | 180 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3ef010, Length_ptr = 0xa2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 181 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3e1d80, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3e2100, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 178 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1608da0, Length_ptr = 0x9e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 302 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f6230, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160d440, Length_ptr = 0xb0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 191 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3e2b80, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15045a0, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 213 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160dc80, Length_ptr = 0xae, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f6430, Length_ptr = 0xf6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 446 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3e31a0, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14fa380, Length_ptr = 0x9c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3e3360, Length_ptr = 0xd6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14fa850, Length_ptr = 0x9c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
Information | Value |
---|---|
Sequence Length | 1663 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1038cb0, Length_ptr = 0xe2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001cf1201, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x10397f0, Length_ptr = 0xaa, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x14f6630, Length_ptr = 0xf0, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1044120, Length_ptr = 0xb8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1048fb0, Length_ptr = 0xde, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x10380f0, Length_ptr = 0xa6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x14f6830, Length_ptr = 0xf0, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xf89580, Length_ptr = 0xb6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 457 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1049af0, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf993e0, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf99ac0, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f6e30, Length_ptr = 0xee, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 431 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfa2e00, Length_ptr = 0xb6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x397940, Length_ptr = 0x112, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1049fa0, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 244 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf94620, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x104a270, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 267 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfa3d00, Length_ptr = 0xb0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8450, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfae9f0, Length_ptr = 0xa2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 319 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f7230, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e450, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1620710, Length_ptr = 0xb8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 116 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x104a810, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 51 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 142 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf94b60, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 149 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1572030, Length_ptr = 0xde, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 266 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf950a0, Length_ptr = 0xd2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ce2201, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1574ff0, Length_ptr = 0x9a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 12 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Sequence Length | 577 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1576330, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x157fe30, Length_ptr = 0xb8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1582d90, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x157ffd0, Length_ptr = 0xc6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 172 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1580da0, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 239 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1572b70, Length_ptr = 0xde, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1572e40, Length_ptr = 0xdc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 146 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1585790, Length_ptr = 0xac, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 141 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1587a10, Length_ptr = 0xb4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 124 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f7c30, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 179 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15c5e70, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
Information | Value |
---|---|
Sequence Length | 81 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14458b0, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cefbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf13b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf13b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
Information | Value |
---|---|
Sequence Length | 82 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1449330, Length_ptr = 0xb6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 85 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd27d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd27d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 402 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x148a780, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x145e470, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd23b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd23b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144beb0, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 233 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x145e920, Length_ptr = 0xe4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce23b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce23b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1493720, Length_ptr = 0xac, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001228010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00169a301, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 139 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x148b620, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce0bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001efa401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 188 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1441930, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f8830, Length_ptr = 0xf4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
Information | Value |
---|---|
Sequence Length | 181 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x148c320, Length_ptr = 0xbc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f8a30, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 152 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x148c660, Length_ptr = 0xba, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cef7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 209 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x148cc10, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f8c30, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 251 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1496ea0, Length_ptr = 0xb4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8540, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8540, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c4510, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 222 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1441cb0, Length_ptr = 0xd2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14bfe80, Length_ptr = 0x9a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 150 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x145f370, Length_ptr = 0xdc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 188 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c02a0, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 180 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1499f60, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
Information | Value |
---|---|
Sequence Length | 400 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x145fa00, Length_ptr = 0xe6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16b0350, Length_ptr = 0xae, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf3bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf3bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf3bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf3bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x145fbe0, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 184 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16b0950, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf37d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf37d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf37d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf37d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 268 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c2f50, Length_ptr = 0x9c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf33b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf33b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c4710, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd43b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 42 |
Process | Amount |
---|---|
Process 14 (svchost.exe, PID: 780) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xbfed50, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3d9f80, Length_ptr = 0x1e, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x30c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x30c |
_wcsnicmp | _String1 = , _String2 = Windows, _MaxCount = 0x7, ret_val_out = 58849 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x30c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x30c |
Information | Value |
---|---|
Sequence Length | 60 |
Process | Amount |
---|---|
Process 14 (svchost.exe, PID: 780) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x30c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x644, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x30c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800256eb20, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x30c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x30c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 133 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x158ab90, Length_ptr = 0x9e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaf138, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xcaf548, Length_ptr = 0x96, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 10 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Process 13 (svchost.exe, PID: 684) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xd2e9f8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef8287a70, Length_ptr = 0x20, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002ee5001 |
ProbeForRead | Address_ptr = 0xd2eac8, Length_ptr = 0x4, Alignment = 0x1 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
ObReferenceObjectByHandle | Handle_unk = 0x6d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880023049d0, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 413 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xd2d4c0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1d9d870, Length_ptr = 0x70, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\netip6.inf_loc, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = System32\DriverStore\en-US\netip6.inf_loc, _String2 = $NtUninstallQ923283$, _MaxCount = 0x28, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = System32\DriverStore\en-US, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = System32\DriverStore\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Windows\System32, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = System32, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001f3a500, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001f3a500, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x35c |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 210 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f29ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f29ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f2aad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f2aad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f2bad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f2bad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f2cad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f2cad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f2db60 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f2db60, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 586 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 105 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f31ac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f31ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f32ac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f32ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
Information | Value |
---|---|
Sequence Length | 563 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f33ac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f33ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f34ac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f34ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f35ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f35ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f36ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f36ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f37ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f37ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f38ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f38ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f39ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f39ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3aad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f3aad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3bad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f3bad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3cad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f3cad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3dad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f3dad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3ead0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f3ead0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3fad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f3fad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f50ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f50ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8ebc8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8ea28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b0100, Length_ptr = 0x5e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f5dd00 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f5dd00, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f5ed00 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f5ed00, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f5fd00 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f5fd00, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f60d00 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f60d00, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f61b60 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f61b60, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
Information | Value |
---|---|
Sequence Length | 114 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x13c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001edcc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001edcc50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x128, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa8003102090, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003102090, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaef68, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaef68, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x128, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaf470, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7feff2a5830, Length_ptr = 0x40, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa8002c21ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002c21ea0, ret_val_ptr_out = 0x3 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 1089 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a114d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a114d0, ret_val_ptr_out = 0x9 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaebd8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xcaf258, Length_ptr = 0x56, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa800328b701 | ||||
ProbeForRead | Address_ptr = 0xcaeca8, Length_ptr = 0x4, Alignment = 0x1 | ||||
ProbeForRead | Address_ptr = 0xcaede8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xcaede8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xcaf088, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xcaf4e8, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x148, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Accessibility, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AspNetMMCExt, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = AuditPolicyGPManagedStubs.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = BDATunePIA, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/ComSvcConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/dfsvc.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/MSBuild.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/SMSvcHost.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/WsatConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ComSvcConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CustomMarshalers, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = CustomMarshalers, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = dfsvc, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehCIR, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehexthost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiActivScp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiBmlDataCarousel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiExtens, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiiTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiProxy, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiTVMSMusic, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiUPnP, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiUserXp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiVidCtl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiwmp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehiWUapi, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehRecObj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = ehshell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = EventViewer, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = loadmxf, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 23 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcepg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = MCESidebarCtrl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcglidhostobj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcplayerinterop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcstore, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcstoredb, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = mcupdate, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Mcx2Dvcs, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Activities.Build, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.ApplicationId.Framework, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.ApplicationId.RuleWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Conversion.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Engine, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Engine, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Framework, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Framework, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x30, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x31, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Tasks.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x32, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Utilities, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x33, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Build.Utilities.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x34, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.CSharp, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x35, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.GroupPolicy.AdmTmplEditor, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x36, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.GroupPolicy.Interop, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x37, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.GroupPolicy.Reporting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x38, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Ink, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x39, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Internal.Tasks.Dataflow, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.ManagementConsole, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Bml, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.iTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.iTv.Hosting, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x40, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.iTV.Media, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x41, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.ITVVM, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x42, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Mheg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x43, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Playback, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x44, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Shell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x45, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.Sports, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x46, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.TV.Tuners.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x47, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.MediaCenter.UI, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x48, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Diagnostics, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x49, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x4a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Utility, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x4b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.ConsoleHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x4c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Editor, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x4d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.GPowerShell, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x4e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.GraphicalHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x4f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.PowerShell.Security, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x50, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x51, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x52, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x53, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x54, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x55, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x56, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x57, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Transactions.Bridge, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x58, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Transactions.Bridge.Dtc, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x59, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.Transactions.Bridge.Dtc, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x5a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x5b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x5c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic.Activities.Compiler, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x5d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic.Compatibility, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x5e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Microsoft.VisualBasic.Compatibility.Data, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x5f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 245 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15ce310, Length_ptr = 0x80, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32f150, Length_ptr = 0x72, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 335 |
Process | Amount |
---|---|
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d7d0, Object_out = 0xfffff8a003e4c7f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003e4c7f0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d400, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d280, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0xa |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x20040, Length_ptr = 0x50, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
ProbeForRead | Address_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x20040, Length_ptr = 0xe, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b59dd2, Length_ptr = 0x86, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b59548, Length_ptr = 0x7e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b593c8, Length_ptr = 0x84, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800234d380, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x58, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800234d388, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800234d408, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = en-US, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d030, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d120, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800234d380, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3ee990, Length_ptr = 0xa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800234d380, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b5a740, Length_ptr = 0xa0, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x5a3948, Length_ptr = 0x8c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7e4f80, Length_ptr = 0x2e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b5a9ce, Length_ptr = 0x78, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b597f4, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x5a3948, Length_ptr = 0x8c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x7 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7e4f80, Length_ptr = 0x2e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b5aa48, Length_ptr = 0x56, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x5a3948, Length_ptr = 0x8c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x6 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7e4b80, Length_ptr = 0x2e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b594ec, Length_ptr = 0x2a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x5a3948, Length_ptr = 0x8c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7e4b80, Length_ptr = 0x2e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b59244, Length_ptr = 0x3e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001820580, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001820580, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x5a3948, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27db78, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x5a3948, Length_ptr = 0x68, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234da80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x27db78, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x5a3948, Length_ptr = 0x68, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234da80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 |
IoAllocateMdl | VirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoAllocateMdl | VirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002a7fe70 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002a7fe70, AccessMode_unk = 0xfffffa8002a7fe01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002a7fe70 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002a7fe70, MemoryDescriptorList_unk_out = 0xfffffa8002a7fe70 |
IoFreeMdl | Mdl_unk = 0xfffffa8002a7fe70 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 |
IoAllocateMdl | VirtualAddress_ptr = 0x3ef69c, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
ProbeForRead | Address_ptr = 0x27db78, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x5a3948, Length_ptr = 0x78, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7efe1440, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7e5b88, Length_ptr = 0x34, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x27db78, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x74dd1670, Length_ptr = 0x7c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
PsGetCurrentProcessId | ret_val_unk_out = 0x99c |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234da80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 27 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 119 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002e65600 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 |
Information | Value |
---|---|
Sequence Length | 149 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x158b7f0, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 61 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f05a10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05a10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16bc8e0, Length_ptr = 0xcc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 334 |
Process | Amount |
---|---|
Process 20 (svchost.exe, PID: 1040) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x184df08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a7a1d0, Length_ptr = 0x8a, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
_wcsnicmp | _String1 = Windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = system32\WDI\BootPerformanceDiagnostics_SystemData.bin, _String2 = $NtUninstallQ923283$, _MaxCount = 0x35, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
_wcsnicmp | _String1 = Windows\System32\wdi, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = System32\wdi, _String2 = $NtUninstallQ923283$, _MaxCount = 0xb, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a95d70, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = System32\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a95d70, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001f41c00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001f41c00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a95d70, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a95d70, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
Information | Value |
---|---|
Sequence Length | 39 |
Process | Amount |
---|---|
Process 20 (svchost.exe, PID: 1040) | 1 |
Symbol | Parameters |
---|---|
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x7c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffffa8000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88002a96a28, ret_val_unk_out = 0x0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a96a20, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x2 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a967a0, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x410 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bfe340 |
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 56 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14e2bf0, Length_ptr = 0xdc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 51 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x337d10, Length_ptr = 0x130, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 245 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14cb930, Length_ptr = 0xba, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 31 |
Process | Amount |
---|---|
Process 31 (mscorsvw.exe, PID: 2128) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002743470 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002eaaa20 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002eaaa02, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002743470 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002eaaa20 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002eaaa02, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002743470 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002eaaa20 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002eaaa02, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 230 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e483c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e483c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c4710, Length_ptr = 0xea, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e483c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e483c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c4910, Length_ptr = 0xea, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 180 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002f5a600 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619590, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000438, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619640, Object_out = 0xfffff8a001f3ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f3ec70, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000440, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619640, Object_out = 0xfffff8a00115ffa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00115ffa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002f5a600 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000440, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619470, Object_out = 0xfffff8a00115ffa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00115ffa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000438, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619520, Object_out = 0xfffff8a001f3ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f3ec70, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619520, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046195f0, Object_out = 0xfffffa80030b1360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030b1360, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046192a0, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046192a0, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046192a0, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046192a0, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619520, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 137 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047886d0, Object_out = 0xfffffa8002e42920, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e42920, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001469c00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003289190 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003289190, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003289190 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003289190, MemoryDescriptorList_unk_out = 0xfffffa8003289190 |
IoFreeMdl | Mdl_unk = 0xfffffa8003289190 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001469c00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003289190 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003289190, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003289190 |
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003289190, MemoryDescriptorList_unk_out = 0xfffffa8003289190 |
IoFreeMdl | Mdl_unk = 0xfffffa8003289190 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047886d0, Object_out = 0xfffffa8002e425b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e425b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047886d0, Object_out = 0xfffffa8002e42050, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e42050, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Sequence Length | 123 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c4d10, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff8000047c, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff8000047c, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff8000047c, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000047c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff8000047c, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000047c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 17 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xd4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002a682b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002a682b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb23a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb23a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 1011 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132f308, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132f058, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefcd72d40, Length_ptr = 0x64, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002f4fb01 | ||||
ProbeForRead | Address_ptr = 0x132f128, Length_ptr = 0x4, Alignment = 0x1 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132f378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132f1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefcd72db0, Length_ptr = 0x6a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132f378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132f1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefcd72e20, Length_ptr = 0x60, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132f2a8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132f108, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefcd73020, Length_ptr = 0x4a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132efc8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ee28, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefcd73070, Length_ptr = 0x18, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132f2f8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132f158, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefcd72ee0, Length_ptr = 0x58, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x132f210, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0740 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0740, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0740 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0740, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007ee8210 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007ee8210, MemoryDescriptorList_unk = 0xfffffa80025d0740 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0740, MemoryDescriptorList_unk_out = 0xfffffa80025d0740 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80025d0740 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ebf8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ea58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ebe8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ef38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ed98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ef38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ed98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132eff8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x132f040, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb3540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb3540, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ebf8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ea58, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ebe8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ef38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ed98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ef38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ed98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132eff8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x132f040, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ebe8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132eff8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x132f040, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ebe8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x132eff8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x132f040, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x132f170, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007ef8170 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007ef8170, MemoryDescriptorList_unk = 0xfffffa80025d0e70 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80025d0e70 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x132f170, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007ef9170 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007ef9170, MemoryDescriptorList_unk = 0xfffffa80025d0e70 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80025d0e70 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x132f170, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efa170 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007efa170, MemoryDescriptorList_unk = 0xfffffa80025d0e70 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80025d0e70 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x132f170, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efb170 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007efb170, MemoryDescriptorList_unk = 0xfffffa80025d0e70 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80025d0e70 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x132f180, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efc180 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007efc180, MemoryDescriptorList_unk = 0xfffffa80025d0e70 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80025d0e70 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x132f180, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efd180 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007efd180, MemoryDescriptorList_unk = 0xfffffa80025d0e70 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80025d0e70 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 101 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c5310, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000430, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000430, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000430, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000430, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 31 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000440, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880027751e0, Object_out = 0xfffffa8002eb4620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4620, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 237 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0810 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0810 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f0c0d0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f0c0d0, MemoryDescriptorList_unk = 0xfffffa80025d0810 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0810, MemoryDescriptorList_unk_out = 0xfffffa80025d0810 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0810 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc6 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0810 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0810 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f0d0d0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f0d0d0, MemoryDescriptorList_unk = 0xfffffa80025d0810 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0810, MemoryDescriptorList_unk_out = 0xfffffa80025d0810 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0810 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc6 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0810 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0810 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f0e0d0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f0e0d0, MemoryDescriptorList_unk = 0xfffffa80025d0810 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0810, MemoryDescriptorList_unk_out = 0xfffffa80025d0810 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0810 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc6 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0810 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0810 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f0f0d0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f0f0d0, MemoryDescriptorList_unk = 0xfffffa80025d0810 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0810, MemoryDescriptorList_unk_out = 0xfffffa80025d0810 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0810 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc6 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x132e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 397 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x166d2c0, Length_ptr = 0xfa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000458, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000458, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000458, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000458, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3a3f00, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000458, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000458, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000458, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000458, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000458, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000458, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x166d4e0, Length_ptr = 0x106, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000458, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000458, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000458, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 17 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 163 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x166de70, Length_ptr = 0xfa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800006dc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800006dc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800006dc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800006dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800006dc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800006dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c5b10, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 935 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002ecfe00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002ecfe00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f7cac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f7cac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f7dac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f7dac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f7eac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f7eac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f7fac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f7fac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f90ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f90ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f91ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f91ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f92ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f92ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f93ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f93ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f94ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f94ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f95ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f95ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f96ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f96ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f97ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f97ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f98ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f98ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f99ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f99ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f9aad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f9aad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f9bad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f9bad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 512 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5b00, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5b00, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc4ac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fc4ac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc5ac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fc5ac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc6ac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fc6ac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc7ac0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fc7ac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc8ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fc8ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc9ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fc9ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcaad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fcaad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcbad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fcbad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fccad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fccad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcdad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fcdad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcead0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fcead0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcfad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fcfad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fd0ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fd0ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fd1ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fd1ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fd2ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fd2ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
Information | Value |
---|---|
Trigger | KiRetireDpcList+0x26a |
Start Address | 0xfffffa8001bc4b12 |
Information | Value |
---|---|
Sequence Length | 10 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80031a6e40 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa800311b170 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa800311b102, SpinLock_unk_out = 0xfffffa8001c3a658 |
Information | Value |
---|---|
Sequence Length | 17 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Process 18 (svchost.exe, PID: 264) | 1 |
Process 11 (svchost.exe, PID: 564) | 1 |
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa800303b760 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80018b09d0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa80018b0902, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 7 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8003147100 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 13 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80030fac30 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80031fc070 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa80031fc002, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x9b8 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 25 (svchost.exe, PID: 1692) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x488 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 2 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 189 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80025a5400 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa80025a5402, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002bace40 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80030b76e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80027670e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002767002, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80030b76e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80027670e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002767002, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80030b76e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80030b76e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80027670e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002767002, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80030b76e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80027670e0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002767002, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x8f0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80031f2170 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x8f0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x8f0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002732670 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002732670 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002778c20 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa80025410d0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002541002, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002743470 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
NdisGetDataBuffer | ret_val_out = 0xfffffa8002fb7380 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002fb7302, SpinLock_unk_out = 0xfffffa8001c3a658 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x8f0 |
Information | Value |
---|---|
Sequence Length | 11 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 15 (svchost.exe, PID: 836) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x4b4 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x4b4 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be0000+0x661 |
Start Address | 0xfffff80002719480 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 267 |
Process 37 (googleupdate.exe, PID: 1000) | 2 |
Process 8 (services.exe, PID: 448) | 1 |
Process 11 (svchost.exe, PID: 564) | 1 |
Process 15 (svchost.exe, PID: 836) | 1 |
Process 16 (svchost.exe, PID: 860) | 4 |
Process 18 (svchost.exe, PID: 264) | 7 |
Process 20 (svchost.exe, PID: 1040) | 1 |
Process 26 (taskeng.exe, PID: 1876) | 2 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 289 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0x132f358, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e9f340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e9f340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x132eec8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x132ed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcd731a0, Length_ptr = 0x80, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x132eec8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x132ed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcd73230, Length_ptr = 0x8a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000be40d0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000be40d0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000be50d0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000be50d0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000be60d0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000be60d0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000be70d0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000be70d0, MemoryDescriptorList_unk = 0xfffffa80027896b0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 |
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x132e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x15c |
ProbeForRead | Address_ptr = 0x132e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be0000+0x66d |
Start Address | 0xfffff80002719514 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Process 2 (System, PID: 4) | 225 |
Process 11 (svchost.exe, PID: 564) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be0000+0x6b5 |
Start Address | 0xfffff800027194b0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Process 2 (System, PID: 4) | 265 |
Process 11 (svchost.exe, PID: 564) | 1 |
Symbol | Parameters |
---|---|
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x75e |
Start Address | 0xfffff800026ef420 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 1 |
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Process 8 (services.exe, PID: 448) | 2 |
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Process 11 (svchost.exe, PID: 564) | 3 |
Process 13 (svchost.exe, PID: 684) | 1 |
Process 14 (svchost.exe, PID: 780) | 1 |
Process 16 (svchost.exe, PID: 860) | 1 |
Process 18 (svchost.exe, PID: 264) | 6 |
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
Information | Value |
---|---|
Sequence Length | 53 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1c8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa80030a7b50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030a7b50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x104, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800251a510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800251a510, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb1e00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb1e00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 573 |
Process | Amount |
---|---|
Process 15 (svchost.exe, PID: 836) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdbb8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fda18, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdba8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e624a0, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdef8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fdd58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdef8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fdd58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdfb8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x21fe000, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa8002ed4200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002ed4200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdbb8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fda18, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdba8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e624a0, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdef8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fdd58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdef8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fdd58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bde000+0x328 |
Start Address | 0xfffff800026d3770 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 2 |
Process 37 (googleupdate.exe, PID: 1000) | 2 |
Process 38 (googleupdate.exe, PID: 2496) | 2 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 2 |
Process 8 (services.exe, PID: 448) | 4 |
Process 41 (googleupdate.exe, PID: 2440) | 2 |
Process 11 (svchost.exe, PID: 564) | 5 |
Process 2 (System, PID: 4) | 12 |
Process 14 (svchost.exe, PID: 780) | 2 |
Process 13 (svchost.exe, PID: 684) | 2 |
Process 16 (svchost.exe, PID: 860) | 2 |
Process 18 (svchost.exe, PID: 264) | 8 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bde000+0x37d |
Start Address | 0xfffff800026d6c60 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 2 |
Process 37 (googleupdate.exe, PID: 1000) | 2 |
Process 38 (googleupdate.exe, PID: 2496) | 2 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 2 |
Process 8 (services.exe, PID: 448) | 4 |
Process 41 (googleupdate.exe, PID: 2440) | 2 |
Process 11 (svchost.exe, PID: 564) | 5 |
Process 2 (System, PID: 4) | 12 |
Process 14 (svchost.exe, PID: 780) | 2 |
Process 13 (svchost.exe, PID: 684) | 2 |
Process 16 (svchost.exe, PID: 860) | 2 |
Process 18 (svchost.exe, PID: 264) | 8 |
Symbol | Parameters |
---|---|
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bc9000+0x742 |
Start Address | 0xfffff800029a8150 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Process 8 (services.exe, PID: 448) | 2 |
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Process 11 (svchost.exe, PID: 564) | 3 |
Process 13 (svchost.exe, PID: 684) | 1 |
Process 14 (svchost.exe, PID: 780) | 1 |
Process 16 (svchost.exe, PID: 860) | 1 |
Process 18 (svchost.exe, PID: 264) | 4 |
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003219830, Object_out = 0xfffffa80018fe510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 43 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 161 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1560b70, Length_ptr = 0xde, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 167 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144e720, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 203 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16bce20, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bc9000+0x78d |
Start Address | 0xfffff800026d5e60 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Process 8 (services.exe, PID: 448) | 2 |
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Process 11 (svchost.exe, PID: 564) | 3 |
Process 13 (svchost.exe, PID: 684) | 1 |
Process 14 (svchost.exe, PID: 780) | 1 |
Process 16 (svchost.exe, PID: 860) | 1 |
Process 18 (svchost.exe, PID: 264) | 4 |
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffffa80018fe510, ret_val_ptr_out = 0xf |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c02000+0x70 |
Start Address | 0xfffff800026cb153 |
Information | Value |
---|---|
Sequence Length | 377 |
Process | Amount |
---|---|
Process 8 (services.exe, PID: 448) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xe1d9e0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xe1dd00, Length_ptr = 0x88, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
ProbeForRead | Address_ptr = 0xe1d9e0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778cef00, Length_ptr = 0x2a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1dc58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778cf040, Length_ptr = 0x9a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
ProbeForRead | Address_ptr = 0xe1dc58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xe1dd00, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1d5f0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xe1d800, Length_ptr = 0x56, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\AppPatch\AppPatch64\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = AppPatch\AppPatch64\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x1e, ret_val_out = 61 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003219830, Object_out = 0xfffffa80018fe510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80018fe510, ret_val_ptr_out = 0xf |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x368, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a0013e0c70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013e0c70, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0xe1e1f0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce900, Length_ptr = 0x8c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1de50, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xe1e060, Length_ptr = 0x56, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\AppPatch\AppPatch64\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = AppPatch\AppPatch64\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x1e, ret_val_out = 61 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x368, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001ba2810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2810, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0xe1d9c0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xe1dbd0, Length_ptr = 0x56, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
_wcsnicmp | _String1 = Windows\AppPatch\AppPatch64\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = AppPatch\AppPatch64\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x1e, ret_val_out = 61 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x368, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001ba2810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2810, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x320, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80018fe510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80018fe510, ret_val_ptr_out = 0xe |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002bf8b30 |
strncpy | _Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
_strnicmp | _Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x358, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a000d2fdd0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d2fdd0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x364, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80030f7490, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030f7490, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x364, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa8002519060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002519060, ret_val_ptr_out = 0x24 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1f070, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1553a0, Length_ptr = 0x14, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1f070, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160ba0, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1f0b0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1602d0, Length_ptr = 0xa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1f0f0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16c970, Length_ptr = 0xe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1f130, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16d200, Length_ptr = 0xc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1f070, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16d200, Length_ptr = 0xc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1f020, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16d200, Length_ptr = 0xc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xe1efe0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16d200, Length_ptr = 0xc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x1c0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa8002e08a70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e08a70, ret_val_ptr_out = 0xbc |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 9 |
Process | Amount |
---|---|
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1c3898, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x30664, Length_ptr = 0x20, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b5324e, Length_ptr = 0x84, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
Information | Value |
---|---|
Sequence Length | 857 |
Process | Amount |
---|---|
Process 37 (googleupdate.exe, PID: 1000) | 1 |
Process 38 (googleupdate.exe, PID: 2496) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e110, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoAllocateMdl | VirtualAddress_ptr = 0x38f3d8, Length = 0x108, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b52fc0, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b52fa0, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003eec580, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003eec580, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x422550, Length_ptr = 0x64, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b52f80, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f03960, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f03960, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38f05c, Length_ptr = 0x1c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003ef1300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003ef1300, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x76711870, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
ProbeForRead | Address_ptr = 0x12ddf8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1c3060, Length_ptr = 0x2c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a0004d7840, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0004d7840, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003e71810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003e71810, ret_val_ptr_out = 0x3 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x764c0350, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x42186c, Length_ptr = 0x20, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a001ed4b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed4b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0xd |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38f20c, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f09570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f09570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38eee0, Length_ptr = 0x14, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f57fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f57fc0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x423188, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x423188, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38eb40, Length_ptr = 0x14, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f0fc00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f0fc00, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38e814, Length_ptr = 0x16, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f59da0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f59da0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38e4e8, Length_ptr = 0x1a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f68610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f68610, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38f20c, Length_ptr = 0x16, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a000bf4fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000bf4fc0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38ee6c, Length_ptr = 0x16, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f59ec0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f59ec0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38eacc, Length_ptr = 0x12, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a000bf3de0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000bf3de0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38e7a0, Length_ptr = 0x14, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f13fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f13fc0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38e7a0, Length_ptr = 0xe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f0f800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f0f800, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38e474, Length_ptr = 0x12, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003ef0610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003ef0610, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38e3b4, Length_ptr = 0x8e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x38f378, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x763f6c08, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0xac, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x40, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x766d18d0, Length_ptr = 0x84, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x48, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
_wcsnicmp | _String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x48, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38e630, Length_ptr = 0x12, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a000bf0b50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000bf0b50, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcess | ret_val_out = 0xfffffa800251c060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoAllocateMdl | VirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8003138801 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 |
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 |
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 |
ProbeForRead | Address_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1c38d8, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
PsGetCurrentProcessId | ret_val_unk_out = 0x3e8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x48, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a001e55520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e55520, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 15 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x141eab0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x749bf8, Length_ptr = 0xe2, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x141eab0, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x749bf8, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
Information | Value |
---|---|
Sequence Length | 3253 |
Process | Amount |
---|---|
Process 11 (svchost.exe, PID: 564) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00030abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Control, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = Control, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwQueryKey | KeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 1290 |
Process | Amount |
---|---|
Process 11 (svchost.exe, PID: 564) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffffa8002519060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002519060, ret_val_ptr_out = 0x1e | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffffa800327ed10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800327ed10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001216060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001216060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165dce8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x165e4c0, Length_ptr = 0x6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e268, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd158, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e518, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd158, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f44060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f44060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cda670, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cda670, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b76670, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b76670, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f02670, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f02670, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001800060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001800060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd2670, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd2670, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e268, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a68, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e518, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a68, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e1e060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e1e060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f1e530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f1e530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ce2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce2530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ce2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce2530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a00182a060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00182a060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f44060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f44060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd2530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x3a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cf3530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cf3530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x3a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x3a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x3a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x3a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001800060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001800060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x3a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ce0530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce0530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x64, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd8530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x64, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x64, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x64, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x64, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x64, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cf7530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cf7530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x64, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e1e060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001e1e060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cff530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cff530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f4f060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f4f060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0011e3060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0011e3060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ce8530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce8530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ced060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ced060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0019d0060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019d0060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x30, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd4530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd4530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x30, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x30, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x30, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x30, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ceb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ceb060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x30, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0019d6060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019d6060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x34, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001d01530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001d01530, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4dd150, Length_ptr = 0x34, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d7a60, Length_ptr = 0x34, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x234 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 1247 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xf4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80031fb9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031fb9b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xf8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800311a230, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800311a230, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x100, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003206430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003206430, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xfc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800311c960, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800311c960, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x104, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002ff51b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002ff51b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xf0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80030b58d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80030b58d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003230380, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003230380, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xd8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80032083f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80032083f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xd0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80032084b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80032084b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xd4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003208570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003208570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003226f10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003226f10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003284790, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003284790, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003251fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003251fc0, ret_val_ptr_out = 0x5 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xb0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xb4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002df66c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002df66c0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003145f60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003145f60, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0xffffffffffffffff, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88004459a50, ret_val_unk_out = 0x0 | ||||
ZwQueryInformationProcess | ProcessHandle_unk = 0xffffffff800007b0, ProcessInformationClass_unk = 0x0, ProcessInformationLength = 0x30, ProcessInformation_ptr_out = 0xfffff88004459a58, ReturnLength_ptr_out = 0x0, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
PsLookupProcessByProcessId | ProcessId_unk = 0x8ac, Process_unk_out = 0xfffff880044598b8, ret_val_unk_out = 0x0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x104, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031529e0, ret_val_ptr_out = 0x3f | ||||
_stricmp | _Str1 = GoogleUpdate.e, _Str2 = svchost.exe, ret_val_out = -12 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwClose | Handle_unk = 0xffffffff800007b0, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044597f0, Object_out = 0xfffffa80031529e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031529e0, ret_val_ptr_out = 0x3f | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x284, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003156920, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003156920, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x280, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x28c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800321c6c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800321c6c0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x288, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x27c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800313d560, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800313d560, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800313c8d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800313c8d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x208, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80018c5be0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80018c5be0, ret_val_ptr_out = 0x17 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000dbf3c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000dbf3c0, ret_val_ptr_out = 0x24 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80031627d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031627d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1f0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003162590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003162590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x194, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800326b310, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800326b310, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x198, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002fb4be0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb4be0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x19c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80031531e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031531e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1a0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302d7d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302d7d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1a4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302d850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302d850, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1a8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002547940, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002547940, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302c8b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302c8b0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003152120, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003152120, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x18c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003163070, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003163070, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x180, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800311ace0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800311ace0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x184, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800304ae90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800304ae90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x168, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003153bc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003153bc0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x16c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003153c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003153c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x170, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302d8e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302d8e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x174, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302d9a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302d9a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x178, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002e95440, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e95440, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x17c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002dd5180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dd5180, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002fc8070, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002fc8070, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80025201e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80025201e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003028ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003028ef0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xdc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003028fb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003028fb0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xcc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003028bc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003028bc0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003028c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003028c80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002dd7e60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dd7e60, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x7c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x200, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x70, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002dec7d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dec7d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x64, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002f586d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f586d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x68, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80032302c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80032302c0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x6c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800304cb80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800304cb80, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x74, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002dec710, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dec710, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x78, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000f92500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f92500, ret_val_ptr_out = 0xa | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x210, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000f92500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f92500, ret_val_ptr_out = 0x9 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x11c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000305330, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000305330, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002fbbe60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002fbbe60, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80031fc3e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031fc3e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x21dc18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000305330, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000305330, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x34, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002fa0ab0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002fa0ab0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x12c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800304cac0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800304cac0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800319b370, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800319b370, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x30, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002b16120, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002b16120, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0xffffffffffffffff, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88004459a50, ret_val_unk_out = 0x0 | ||||
ZwQueryInformationProcess | ProcessHandle_unk = 0xffffffff800007b0, ProcessInformationClass_unk = 0x0, ProcessInformationLength = 0x30, ProcessInformation_ptr_out = 0xfffff88004459a58, ReturnLength_ptr_out = 0x0, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
PsLookupProcessByProcessId | ProcessId_unk = 0x8ac, Process_unk_out = 0xfffff880044598b8, ret_val_unk_out = 0x0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x104, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031529e0, ret_val_ptr_out = 0x24 | ||||
_stricmp | _Str1 = GoogleUpdate.e, _Str2 = svchost.exe, ret_val_out = -12 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2c700 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ZwClose | Handle_unk = 0xffffffff800007b0, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044597f0, Object_out = 0xfffffa80031529e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80031529e0, ret_val_ptr_out = 0x24 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 1522 |
Process | Amount |
---|---|
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27dbf0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x3ef72c, Length = 0x108, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b52fc0, Length_ptr = 0x18, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b52fa0, Length_ptr = 0x18, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003eec580, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003eec580, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7d25b8, Length_ptr = 0x64, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x77b52f80, Length_ptr = 0x18, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f03960, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f03960, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef3b0, Length_ptr = 0x1c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003ef1300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003ef1300, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x76711870, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
ProbeForRead | Address_ptr = 0x27d8d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x5a30d0, Length_ptr = 0x2c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001ed0060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed0060, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003e71810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003e71810, ret_val_ptr_out = 0x3 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x764c0350, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002b99301 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002dc8f40 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0xd | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef560, Length_ptr = 0x18, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f09570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f09570, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef234, Length_ptr = 0x14, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f57fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f57fc0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7d31f8, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7d31f8, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3eee94, Length_ptr = 0x14, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f0fc00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f0fc00, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3eeb68, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f59da0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f59da0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ee83c, Length_ptr = 0x1a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f68610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f68610, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef560, Length_ptr = 0x12, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f80950, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f80950, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef1c0, Length_ptr = 0x12, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a000bf3de0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000bf3de0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3eee94, Length_ptr = 0x14, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f13fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f13fc0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3eee94, Length_ptr = 0xe, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f0f800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f0f800, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3eeb68, Length_ptr = 0x12, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003ef0610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003ef0610, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef560, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a000bf4fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000bf4fc0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef1c0, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f59ec0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003f59ec0, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef560, Length_ptr = 0x18, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7e1010, Length_ptr = 0x7c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef1c0, Length_ptr = 0x18, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7e1010, Length_ptr = 0x7c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\netutils.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\netutils.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\netutils.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\netutils.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\netutils.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef1c0, Length_ptr = 0x14, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7e1010, Length_ptr = 0x78, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\srvcli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x44, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\srvcli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\srvcli.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x44, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\srvcli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\srvcli.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef1c0, Length_ptr = 0x14, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7e1010, Length_ptr = 0x78, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\wkscli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x44, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\wkscli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\wkscli.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x44, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Windows\SysWOW64\wkscli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = SysWOW64\wkscli.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef560, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003eee830, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a003eee830, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef1c0, Length_ptr = 0x16, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a000bf0d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000bf0d60, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3ef560, Length_ptr = 0x16, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7e1768, Length_ptr = 0x7a, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\VERSION.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 | ||||
ProbeForRead | Address_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x27e420, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x99c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 | ||||
strncpy | _Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
_strnicmp | _Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 4265 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x35ff430, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004322430 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004322430, MemoryDescriptorList_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x35ff430, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004323430 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004323430, MemoryDescriptorList_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x35ff430, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004324430 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004324430, MemoryDescriptorList_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x35ff430, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004325430 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004325430, MemoryDescriptorList_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x35ff420, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004326420 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004326420, MemoryDescriptorList_unk = 0xfffffa8002f59580 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f59580 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002b16120, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002b16120, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002b16120, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002b16120, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a200, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a200, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a200, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a200, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x230, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffffa8000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800457aa28, ret_val_unk_out = 0x0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457aa20, Object_out = 0xfffffa8002dee360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dee360, ret_val_ptr_out = 0x2 | ||||
ZwClose | Handle_unk = 0xffffffff80000630, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a7a0, Object_out = 0xfffffa8002dee360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dee360, ret_val_ptr_out = 0x2 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a000d2c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000d2c060, ret_val_ptr_out = 0x15 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x35ff290, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f78290 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f78290, MemoryDescriptorList_unk = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fe918, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fe778, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fe918, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fe778, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35fe918, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x35fe778, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 18839 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f258, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d58c0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f668, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x170f6b0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f258, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d58c0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f668, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x170f6b0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7e0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042827e0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042827e0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7e0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042837e0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042837e0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7e0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042847e0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042847e0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7e0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042857e0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042857e0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042867f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042867f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042877f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042877f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042887f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042887f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042897f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042897f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428a7f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff8800428a7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428b7f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff8800428b7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428c7f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff8800428c7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428d7f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff8800428d7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428e7f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff8800428e7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428f7f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff8800428f7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042907f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042907f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042917f0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042917f0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x170f880, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004292880 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004292880, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f268, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170f0c8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f258, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d58c0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f5a8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170f408, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f5a8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170f408, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170ef08, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170ed68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170ef08, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170ed68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170ef08, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170ed68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f668, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x170f6b0, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f268, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170f0c8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f258, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d58c0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 8224 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1ee08, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1d1ec68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1e768, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1d1e5c8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1e768, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1d1e5c8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1e768, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1d1e5c8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1eec8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1ef10, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1eab8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1d1e918, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1e918, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1eec8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1ef10, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1eab8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1d1e918, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1e918, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1eec8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1ef10, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f040, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e1040 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e1040, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f040, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e2040 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e2040, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f040, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e3040 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e3040, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f040, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e4040 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e4040, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e5050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e5050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e6050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e6050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e7050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e7050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e8050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e8050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e9050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042e9050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ea050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042ea050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042eb050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042eb050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ec050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042ec050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ed050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042ed050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ee050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042ee050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ef050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff880042ef050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004300050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004300050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1f148, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1d1efa8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b0170, Length_ptr = 0x5e, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004301050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004301050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004311050 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88004311050, MemoryDescriptorList_unk = 0xfffffa8002f7e130 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002f7e130 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 1336 |
Process | Amount |
---|---|
Process 14 (svchost.exe, PID: 780) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
ProbeForRead | Address_ptr = 0xbfd338, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fef8286ac0, Length_ptr = 0x1c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x408, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x4a8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eed420, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eed420, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x4a4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x3e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eee5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eee5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa800326b310, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800326b310, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xbfd748, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xbfd7a0, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xbfd8c8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
ProbeForRead | Address_ptr = 0xbfd728, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x34c310, Length_ptr = 0xa4, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xbfd8c8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
ProbeForRead | Address_ptr = 0xbfd728, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x34c310, Length_ptr = 0xa4, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xbfdab0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x20f7110, Length_ptr = 0x5c, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ProbeForRead | Address_ptr = 0xbfddb8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
ProbeForRead | Address_ptr = 0xbfdc18, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fef713ff70, Length_ptr = 0x40, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xbfda60, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x20f6240, Length_ptr = 0x16, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xbfda08, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\dot3api.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\dot3api.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfdbc8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\dot3api.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\dot3api.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfd470, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xbfd700, Length_ptr = 0x16, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xbfd418, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\eappcfg.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\eappcfg.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfd5d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\eappcfg.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\eappcfg.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002eda801 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xbfd810, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002eda801 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002eda801 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xbfd800, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa8002eda801 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x3e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa80030b1240, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa80030b1240, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002968f30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002968f30, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002b06c30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002b06c30, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xbfda60, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x20f6258, Length_ptr = 0x16, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xbfda08, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\wlanhlp.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\wlanhlp.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfdbc8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\wlanhlp.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\wlanhlp.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfd470, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xbfd700, Length_ptr = 0x16, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xbfd418, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\Wlanapi.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\Wlanapi.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfd5d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\Wlanapi.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\Wlanapi.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfce80, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xbfd110, Length_ptr = 0x18, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xbfce28, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\wlanutil.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\wlanutil.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfcfe8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\wlanutil.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\wlanutil.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfd470, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xbfd700, Length_ptr = 0x10, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xbfd418, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x40, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\OneX.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\OneX.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x10, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfd5d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x40, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\OneX.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\OneX.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x10, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfce80, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xbfd110, Length_ptr = 0x18, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xbfce28, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\eappprxy.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\eappprxy.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfcfe8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x48, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\eappprxy.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\eappprxy.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xbfd470, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xbfd700, Length_ptr = 0x16, Alignment = 0x2 | ||||
ProbeForRead | Address_ptr = 0xbfd418, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ea6060 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x30c | ||||
_wcsnicmp | _String1 = Windows\System32\eappcfg.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\eappcfg.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 32036 |
Process | Amount |
---|---|
Process 16 (svchost.exe, PID: 860) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eed420, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eed420, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x84c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xac8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eee5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eee5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xd2e638, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
ProbeForRead | Address_ptr = 0xd2e498, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0xd2e9d0, Length_ptr = 0xec, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xd2ea68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fef8288c50, Length_ptr = 0x6, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xd2ea68, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fef8286ac0, Length_ptr = 0x1c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0xd2d598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d9ee50, Length_ptr = 0x26, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\INF\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = INF\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2, ret_val_out = 69 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\inf\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\inf\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xd2d3e0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d9d870, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\netnwifi.inf_loc, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\DriverStore\en-US\netnwifi.inf_loc, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2a, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\DriverStore\en-US, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 | ||||
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\DriverStore\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 | ||||
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\System32, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 | ||||
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001ed6680, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8a001ed6680, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
_wcsicmp | _Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bf00 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 | ||||
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 | ||||
strncpy | _Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xd2d598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d9ee50, Length_ptr = 0x54, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\DriverStore\en-US\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xd2d658, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d9ee50, Length_ptr = 0x3e, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\INF\netnwifi.PNF, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = INF\netnwifi.PNF, _String2 = $NtUninstallQ923283$, _MaxCount = 0xf, ret_val_out = 69 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eee5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eee5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x84c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xac8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xd2d598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d9ee50, Length_ptr = 0x26, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\INF\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = INF\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2, ret_val_out = 69 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\inf\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\inf\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xd2d3e0, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d9d870, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\netnwifi.inf_loc, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\DriverStore\en-US\netnwifi.inf_loc, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2a, ret_val_out = 79 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xd2d598, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d9ee50, Length_ptr = 0x54, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = System32\DriverStore\en-US\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
_wcsnicmp | _String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
ProbeForRead | Address_ptr = 0xd2d658, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1d9ee50, Length_ptr = 0x3e, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
_wcsnicmp | _String1 = Windows\INF\netnwifi.PNF, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 | ||||
_wcsnicmp | _String1 = INF\netnwifi.PNF, _String2 = $NtUninstallQ923283$, _MaxCount = 0xf, ret_val_out = 69 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eee5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eee5e0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x84c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xac8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002ee1400 | ||||
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x35c | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xa58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 431 |
Process | Amount |
---|---|
Process 41 (googleupdate.exe, PID: 2440) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
IoAllocateMdl | VirtualAddress_ptr = 0x18dfa8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoAllocateMdl | VirtualAddress_ptr = 0x18e830, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
IoAllocateMdl | VirtualAddress_ptr = 0x18dfa8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoAllocateMdl | VirtualAddress_ptr = 0x18e830, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
IoAllocateMdl | VirtualAddress_ptr = 0x18dfb0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoAllocateMdl | VirtualAddress_ptr = 0x40f92c, Length = 0x108, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b52fc0, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b52fa0, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003eec580, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003eec580, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1d2578, Length_ptr = 0x64, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\1.3.26.9\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x77b52f80, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f03960, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f03960, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40f5b0, Length_ptr = 0x1c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003ef1300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003ef1300, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
IoAllocateMdl | VirtualAddress_ptr = 0x18dfa8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoAllocateMdl | VirtualAddress_ptr = 0x18e830, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
IoAllocateMdl | VirtualAddress_ptr = 0x76711870, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ProbeForRead | Address_ptr = 0x18dc98, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xd3090, Length_ptr = 0x2c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003e71810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003e71810, ret_val_ptr_out = 0x3 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
IoAllocateMdl | VirtualAddress_ptr = 0x18dfa8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoAllocateMdl | VirtualAddress_ptr = 0x18e830, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60 |
IoFreeMdl | Mdl_unk = 0xfffffa8003288b60 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
IoAllocateMdl | VirtualAddress_ptr = 0x764c0350, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030a5101 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20 |
IoFreeMdl | Mdl_unk = 0xfffffa8002721a20 |
ProbeForRead | Address_ptr = 0x18df38, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1d186c, Length_ptr = 0x20, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a001822ca0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822ca0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a001a84620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a84620, ret_val_ptr_out = 0xd |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40f760, Length_ptr = 0x18, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f09570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f09570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40f434, Length_ptr = 0x14, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f57fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f57fc0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1d31c0, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
_wcsnicmp | _String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1d31c0, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
_wcsnicmp | _String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a001f3ec90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f3ec90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002465060 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40f094, Length_ptr = 0x14, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f0fc00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f0fc00, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40ed68, Length_ptr = 0x16, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f59da0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f59da0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40ea3c, Length_ptr = 0x1a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f68610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f68610, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40f760, Length_ptr = 0x16, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a000bf4fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000bf4fc0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40f3c0, Length_ptr = 0x16, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f59ec0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f59ec0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40f020, Length_ptr = 0x12, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a000bf3de0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000bf3de0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40ecf4, Length_ptr = 0x14, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f13fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f13fc0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40ecf4, Length_ptr = 0xe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f0f800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003f0f800, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40e9c8, Length_ptr = 0x12, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003ef0610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a003ef0610, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x18df38, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x40e914, Length_ptr = 0x8e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x988 |
Information | Value |
---|---|
Sequence Length | 4880 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 476 |
Process | Amount |
---|---|
Process 13 (svchost.exe, PID: 684) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f1e8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f1e8c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce0530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce0530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce48c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce48c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f438c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f438c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cef530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cef530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf78c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cf78c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d03530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d03530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f4f060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f4f060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cfb8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cfb8c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001aa9060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001aa9060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf3530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cf3530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001aa98c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001aa98c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ec8060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec8060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cec060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cec060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001b87060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b87060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a0019d6060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019d6060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001e28530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e28530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf18c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cf18c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a0017fb530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fb530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f47320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f47320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a00181b060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00181b060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001e528c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e528c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a0011e3060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0011e3060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f028c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f028c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f438c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f438c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce98c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce98c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce28c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce28c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f44060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f44060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cd2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd2530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cec060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cec060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce0530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce0530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cec8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cec8c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf7530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cf7530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cfb8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cfb8c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f4f060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f4f060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ec8060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec8060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cec060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cec060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d05530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d05530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a00181b060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00181b060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce2530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cd8530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd8530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cda530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cda530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f1e530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f1e530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d28060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d28060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001a218c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a218c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2a060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d2a060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f05060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2b060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d2b060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f188c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f188c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d2c060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf3530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cf3530, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d2c8c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2b060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d2b060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001a9a8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a9a8c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f47320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f47320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a0019d0060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019d0060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ec8060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec8060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f05060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d2c8c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cd88c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd88c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cd28c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001cd28c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d038c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d038c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce08c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ce08c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x2ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d078c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001d078c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 14 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000464, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004789030, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000464, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004789090, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 76 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000474, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004789120, Object_out = 0xfffff8a001695510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001695510, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000047c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004789120, Object_out = 0xfffff8a001287600, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001287600, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000045c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004788f20, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000464, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004788f20, Object_out = 0xfffffa8002e40350, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e40350, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Trigger | KiSystemServiceExit+0x1a6 |
Start Address | 0xfffffa8001be4478 |
Information | Value |
---|---|
Sequence Length | 40 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | _wcsicmp+0x44 |
Start Address | 0xfffffa8001be1ece |
Information | Value |
---|---|
Sequence Length | 364 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001ec8ba0, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c97e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97c0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001842780, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c97e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97c0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x36, KeyValueInformation_ptr_out = 0xfffff8a0016abb00, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x2a, KeyValueInformation_deref_Data_out = \Device\NdisWanIpv6, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c97e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97c0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8010, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x32, KeyValueInformation_ptr_out = 0xfffff8a0016abb00, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x26, KeyValueInformation_deref_Data_out = \Device\NdisWanBh, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c97e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97c0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001ec8ba0, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007 |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9810, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = *IfType, DestinationString_out = *IfType |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = *IfType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = *IfType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2c590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2c59c, KeyValueInformation_deref_Data_out = 0x6, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007 |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9810, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = *MediaType, DestinationString_out = *MediaType |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = *MediaType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = *MediaType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2c590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2c59c, KeyValueInformation_deref_Data_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007 |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9810, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = *PhysicalMediaType, DestinationString_out = *PhysicalMediaType |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = *PhysicalMediaType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = *PhysicalMediaType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2c590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2c59c, KeyValueInformation_deref_Data_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x704 |
Start Address | 0xfffff800026dd620 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 107 |
Symbol | Parameters |
---|---|
RtlInitUnicodeString | SourceString = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\8, DestinationString_out = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\8 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x6fe |
Start Address | 0xfffff800026c46a0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 52 |
Symbol | Parameters |
---|---|
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9908, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\8, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c98e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x88a |
Start Address | 0xfffff800026c4740 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 73 |
Symbol | Parameters |
---|---|
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007ec, ValueName = Description, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c98c0, ret_val_unk_out = 0xc0000023 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x6f2 |
Start Address | 0xfffff800026c4640 |
Information | Value |
---|---|
Sequence Length | 8 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 53 |
Symbol | Parameters |
---|---|
ZwClose | Handle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c96c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 411 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3ae870, Length_ptr = 0xba, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37b110, Length_ptr = 0x100, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37b330, Length_ptr = 0x102, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x740 |
Start Address | 0xfffff8000271b1b0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 5 |
Symbol | Parameters |
---|---|
wcsncpy | _Source = Red Hat VirtIO Ethernet Adapter, _Count = 0x100, _Dest_out = Red Hat VirtIO Ethernet Adapter, ret_val_out = Red Hat VirtIO Ethernet Adapter |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x842 |
Start Address | 0xfffff8000271a300 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 5 |
Symbol | Parameters |
---|---|
_snprintf | _Count = 0x73, _Format = \Device\NamedPipe\%s, _Dest_out = \Device\NamedPipe\isapi_dg, ret_val_out = 26 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x938 |
Start Address | 0xfffff8000269bbc8 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 5 |
Symbol | Parameters |
---|---|
RtlInitAnsiString | DestinationString_ptr = 0xfffff880022c9670, SourceString_unk = 0xfffff880022c9920 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x932 |
Start Address | 0xfffff800029b4248 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 5 |
Symbol | Parameters |
---|---|
RtlAnsiStringToUnicodeString | DestinationString_ptr = 0xfffff8a001b8cc48, SourceString = \Device\NamedPipe\isapi_dg, AllocateDestinationString = 1, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bde000+0x2e0 |
Start Address | 0xfffff8000267a28c |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 10 |
Symbol | Parameters |
---|---|
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8001accec0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x81e |
Start Address | 0xfffff8000270c6dc |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 40 |
Symbol | Parameters |
---|---|
_vsnprintf | count = 0x21, format = %u, ap_unk = 0xfffff880022c98d8, string_out = 1, ret_val_out = 1 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bdd000+0xc3f |
Start Address | 0xfffff800026d8540 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80031273d0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bc8000+0xa5a |
Start Address | 0xfffff8000296a9b0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001e14060, ThreadHandle_ptr_out = 0xfffffa8001c2e420, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | PspSystemThreadStartup+0x57 |
Start Address | 0xfffffa8001bc88f4 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 3 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002f81b50 |
rand | ret_val_out = 17888 |
PsTerminateSystemThread | ExitStatus_unk = 0x0 |
Information | Value |
---|---|
Sequence Length | 2199 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa80030e9a00 | ||||
rand | ret_val_out = 12425 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
PsCreateSystemThread | DesiredAccess = 0x0, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bdfef4, StartContext_ptr = 0xfffffa8001c2d8d0, ThreadHandle_ptr_out = 0xfffff880022c9b48, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ZwWaitForSingleObject | Handle_unk = 0xffffffff800007f4, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ZwClose | Handle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 | ||||
strncpy | _Source = System, _Count = 0x11, _Dest_out = System, ret_val_out = System | ||||
RtlInitUnicodeString | SourceString = \Device\Null, DestinationString_out = \Device\Null | ||||
IoGetDeviceObjectPointer | ObjectName = \Device\Null, DesiredAccess_unk = 0x0, FileObject_unk_out = 0xfffff880022c9b40, DeviceObject_unk_out = 0xfffffa8001c2c540, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002516740, ret_val_ptr_out = 0x3 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002db2820 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002f64ce0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8003062510 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002e55aa0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002f7f7b0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa800303a160 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8003133510 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4720, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 13, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b56000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b56000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff8000299db02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8000299db60, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4aa0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b57000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b57000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002986d02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002986df0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4800, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2e, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b58000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b58000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002982802, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002982820, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c6de0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 09, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b59000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b59000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002b4f402, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002b4f440, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4520, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 31, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 03, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5a000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5a000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029b7f02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029b7f80, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4b20, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 33, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5b000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5b000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029d9c02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029d9cdc, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4780, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 7d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 16, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5c000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5c000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029e0702, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029e0780, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4640, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 0c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5d000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5d000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029c5702, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029c5740, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c49e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 29, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5e000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5e000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002987d02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002987d14, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029ca602, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029ca650, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
ZwOpenEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0xc0000034 | ||||
_snwprintf | _Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk1, ret_val_out = 16 | ||||
_snwprintf | _Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk2, ret_val_out = 16 | ||||
_snprintf | _Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par1, ret_val_out = 8 | ||||
_swprintf | _Format = %S, _Dest_out = \??\Par1, ret_val_out = 8 | ||||
_snprintf | _Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par2, ret_val_out = 8 | ||||
_swprintf | _Format = %S, _Dest_out = \??\Par2, ret_val_out = 8 | ||||
_snwprintf | _Count = 0x104, _Format = \BaseNamedObjects\%S, _Dest_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, ret_val_out = 62 | ||||
RtlInitUnicodeString | SourceString = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, DestinationString_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153} | ||||
ZwOpenEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0x0 | ||||
ZwClose | Handle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9560, Object_out = 0xfffffa8002dd1890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dd1890, ret_val_ptr_out = 0x5 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
RtlQueryRegistryValues | RelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff880022c9970, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9660, Object_out = 0xfffff8a0013e0c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013e0c50, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
RtlNtStatusToDosError | Status_unk = 0x0, ret_val_out = 0x0 | ||||
RtlInitUnicodeString | SourceString = \SystemRoot, DestinationString_out = \SystemRoot | ||||
ZwOpenSymbolicLinkObject | DesiredAccess_unk = 0x1, ObjectAttributes_unk = 0xfffff880022c96d0, SymbolicLinkHandle_ptr_out = 0xfffff880022c99a0, ret_val_unk_out = 0x0 | ||||
ZwQuerySymbolicLinkObject | SymLinkObjHandle_unk = 0xffffffff800007f4, LinkTarget_out = \Device\Harddisk0\Partition2\Windows, DataWritten_ptr_out = 0x0, ret_val_unk_out = 0x0 | ||||
wcsncpy | _Source = Windows, _Count = 0x104, _Dest_out = Windows, ret_val_out = Windows | ||||
strncpy | _Source = $NtUninstallQ923283$, _Count = 0x52, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$ | ||||
_snwprintf | _Count = 0x51, _Format = %S, _Dest_out = $NtUninstallQ923283$, ret_val_out = 20 | ||||
_snwprintf | _Count = 0x103, _Format = \SystemRoot\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$, ret_val_out = 32 | ||||
RtlInitUnicodeString | SourceString = \SystemRoot\$NtUninstallQ923283$, DestinationString_out = \SystemRoot\$NtUninstallQ923283$ | ||||
ZwOpenFile | DesiredAccess_unk = 0x100000, ObjectAttributes_ptr = 0xfffff880022c96d0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$, ObjectAttributes_deref_Attributes = 0x240, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, ShareAccess = 0x7, OpenOptions = 0x21, FileHandle_ptr_out = 0xfffff880022c99a0, FileHandle_out = 0xffffffff80000824, IoStatusBlock_unk_out = 0xfffff880022c9700, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c99a8, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa800202b650, ret_val_ptr_out = 0xa | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002c55030, ret_val_ptr_out = 0x2 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9490, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80026b7660 | ||||
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001ecfc00, ThreadHandle_ptr_out = 0xfffffa8001c2c210, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000004 | ||||
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9530, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030e9a00 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x779a17b0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b5f000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5f000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x779a17e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b60000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 38 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa800311f640 |
rand | ret_val_out = 25331 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002fc83c0 |
rand | ret_val_out = 11502 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80031273d0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0 |
Information | Value |
---|---|
Sequence Length | 82 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8003177620 |
rand | ret_val_out = 5970 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001b865b8, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001b86598 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
RtlInitAnsiString | DestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0 |
RtlAnsiStringToUnicodeString | DestinationString_ptr = 0xfffff8a001820b78, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001820b88, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001820b68 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
RtlInitAnsiString | DestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0 |
RtlAnsiStringToUnicodeString | DestinationString_ptr = 0xfffff8a001e9a708, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001e9a718, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001e9a6f8 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000 |
Information | Value |
---|---|
Sequence Length | 1613 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002e72880 | ||||
rand | ret_val_out = 14463 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800435e000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800437b000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002ff5cd8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e64000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9c000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9d000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ec9000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eca000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecb000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecc000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecd000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ece000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecf000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed0000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed1000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed2000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed3000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed4000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed5000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed6000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed7000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed8000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed9000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eda000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edb000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edc000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edd000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ede000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edf000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee0000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee1000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee3000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eec000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x3293e00, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x3293000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0xc0000054 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b93000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b97000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x94000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x94000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9b000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9c000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9d000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9e000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9f000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000bb0000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0xc88fe00, RegionSize_ptr = 0xfffff880045bbb58 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f18c78 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8001ae4000, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88004800000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Trigger | PspSystemThreadStartup+0x57 |
Start Address | 0xfffffa8001bdfef4 |
Information | Value |
---|---|
Sequence Length | 739 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 91 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = HH , _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 101 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -107 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 106 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 107 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = 99 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -105 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -3 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -25 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -27 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = 63 |
_strnicmp | _Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 103 |
_strnicmp | _Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -90 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -97 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -88 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -110 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -94 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -69 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -105 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -98 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -20 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = /, _MaxCount = 0x6, ret_val_out = 68 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -70 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -18 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -77 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = -93 |
_strnicmp | _Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = 8 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 90 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = 8 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 97 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -28 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = -125 |
_strnicmp | _Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = 19 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -139 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -87 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -4 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = System, _MaxCount = 0x6, ret_val_out = 0 |
PsTerminateSystemThread | ExitStatus_unk = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x87e |
Start Address | 0xfffff800026c4b20 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 5 |
Symbol | Parameters |
---|---|
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f53000, ResultLength_ptr_out = 0xfffff880022c9898, ret_val_unk_out = 0xc0000004 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 5 |
Symbol | Parameters |
---|---|
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9530, SystemInformation_ptr_out = 0xfffff8a001f53000, ResultLength_ptr_out = 0xfffff880022c9898, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030e9a00 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be4000+0x7e7 |
Start Address | 0xfffff8800150a010 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
NdisAllocateNetBufferListPool | ret_val_out = 0xfffffa8003205e00 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bc8000+0xaed |
Start Address | 0xfffff80002719490 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 40 |
Symbol | Parameters |
---|---|
KfRaiseIrql | NewIrql_unk = 0xfffff88001517d02, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x836 |
Start Address | 0xfffff8000271acc0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 392 |
Symbol | Parameters |
---|---|
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bc8000+0xc39 |
Start Address | 0xfffff800026e6fe0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 16 |
Symbol | Parameters |
---|---|
IoAllocateMdl | VirtualAddress_ptr = 0xfffff88001517d90, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bc8000+0xc5b |
Start Address | 0xfffff800026e85f0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 16 |
Symbol | Parameters |
---|---|
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bc8000+0xc96 |
Start Address | 0xfffff800026e9de0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 16 |
Symbol | Parameters |
---|---|
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bc8000+0xc9f |
Start Address | 0xfffff800026e6e20 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 16 |
Symbol | Parameters |
---|---|
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be9000+0xa9f |
Start Address | 0xfffff8800157a730 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
NdisInitializeWrapper | ret_val_out = 0xfffffa8003287178 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be9000+0xbb9 |
Start Address | 0xfffff880015805a0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisMRegisterMiniport | ret_val_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be9000+0xbd1 |
Start Address | 0xfffff80002670e70 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
IoGetDriverObjectExtension | DriverObject_unk = 0xfffffa8002513880, ClientIdentificationAddress_ptr = 0x4e4d4944, ret_val_ptr_out = 0xfffffa800326c460 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be9000+0xbed |
Start Address | 0xfffff8000277f0e0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1887 |
Symbol | Parameters |
---|---|
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa800326c460, ret_val_out = 1 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be9000+0xe2f |
Start Address | 0xfffff8800154d2e0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
NdisTerminateWrapper | ret_val_out = 0xfffffa80030e9a50 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001beb000+0x4d6 |
Start Address | 0xfffff880014f4940 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 3 |
Symbol | Parameters |
---|---|
NdisGetVersion | ret_val_out = 0x60014 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001beb000+0x60a |
Start Address | 0xfffff88001517d90 |
Information | Value |
---|---|
Sequence Length | 19 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisMRegisterMiniportDriver | |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c92f0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c92f0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
IoGetDriverObjectExtension | DriverObject_unk = 0xfffffa8002513880, ClientIdentificationAddress_ptr = 0x4e4d4944, ret_val_ptr_out = 0xfffffa8002f8bcd0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2e000 |
Information | Value |
---|---|
Trigger | MiIsAddressValid+0xa8 |
Start Address | 0xfffffa8001beb6bd |
Information | Value |
---|---|
Sequence Length | 604 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd1, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd69, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd2, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd6a, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd3, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd6b, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd4, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd6c, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd5, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd6d, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd6, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd6e, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd7, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd6f, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd9, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd71, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcda, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd72, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcdb, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd73, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcdc, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd74, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcdd, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd75, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcde, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd76, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcdf, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd77, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce1, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd79, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce2, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd7a, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce3, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd7b, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce4, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd7c, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce5, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd7d, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce6, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd7e, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce7, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd7f, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce9, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd81, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcea, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd82, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bceb, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd83, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcec, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd84, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bced, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd85, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcee, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd86, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcef, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd87, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf1, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd89, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf2, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd8a, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf3, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd8b, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf4, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd8c, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf5, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd8d, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf6, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd8e, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf7, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd8f, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf9, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd91, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcfa, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd92, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcfb, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd93, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcfc, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd94, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcfd, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd95, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcfe, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd96, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcff, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd97, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd01, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd99, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd02, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd9a, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd03, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd9b, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd04, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd9c, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd05, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd9d, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd06, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd9e, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd07, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd9f, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd09, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda1, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd0a, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda2, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd0b, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda3, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd0c, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda4, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd0d, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda5, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd0e, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda6, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd0f, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda7, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd11, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda9, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd12, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdaa, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd13, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdab, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd14, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdac, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd15, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdad, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd16, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdae, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd17, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdaf, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd19, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb1, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd1a, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb2, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd1b, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb3, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd1c, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb4, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd1d, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb5, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd1e, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb6, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd1f, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb7, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd21, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb9, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd22, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdba, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd23, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdbb, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd24, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdbc, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd25, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdbd, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd26, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdbe, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd27, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdbf, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd29, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc1, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd2a, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc2, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd2b, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc3, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd2c, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc4, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd2d, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc5, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd2e, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc6, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd2f, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc7, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd31, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc9, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd32, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdca, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd33, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdcb, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd34, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdcc, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd35, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdcd, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd36, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdce, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd37, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdcf, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd39, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd1, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd3a, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd2, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd3b, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd3, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd3c, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd4, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd3d, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd5, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd3e, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd6, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd3f, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd7, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdb8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bdc0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffffa8002f8bd02, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
KeLowerIrql | NewIrql_unk = 0x0 |
NdisMDeregisterMiniportDriver | |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2e000 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x7d6 |
Start Address | 0xfffff800026c4aa0 |
Information | Value |
---|---|
Sequence Length | 55 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 5 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c95e0, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c91e0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007d8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff880022c9268, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0000, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0001, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0002, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0003, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0004, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0005, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0006, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0007, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0008, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0009, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0010, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = 0011, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Properties, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8e90, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c91e0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 163 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c95e0, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c91e0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 22 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 7 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001a795d0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001a79500, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 186 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14cd4b0, Length_ptr = 0x9c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
Information | Value |
---|---|
Sequence Length | 562 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16104f0, Length_ptr = 0xfa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16235e0, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144f920, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16170c0, Length_ptr = 0xb4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 520 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x7b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFontCache, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x7c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x7d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x7e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x7f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemData, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x80, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemDrawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x81, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x82, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemXmlLinq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x83, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Aero, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x84, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Aero, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x85, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.AeroLite, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x86, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Classic, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x87, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Classic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x88, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Luna, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x89, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Luna, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x8a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Royale, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x8b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Royale, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x8c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationUI, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x8d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationUI, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x8e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ReachFramework, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -3 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x8f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ReachFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -3 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x90, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SecurityAuditPoliciesSnapIn, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x91, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SMDiagnostics, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x92, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SMDiagnostics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x93, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SMSvcHost, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x94, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SrpUxSnapIn, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x95, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x96, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x97, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x98, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Activities.Core.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x99, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Activities.DurableInstancing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x9a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Activities.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x9b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.AddIn, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x9c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.AddIn, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x9d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.AddIn.Contract, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x9e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.AddIn.Contract, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x9f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ComponentModel.Composition, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ComponentModel.Composition.Registration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ComponentModel.DataAnnotations, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.ComponentModel.DataAnnotations, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Configuration, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Configuration.Install, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Configuration.Install, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Core, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xa9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xaa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xab, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.DataSetExtensions, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xac, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.DataSetExtensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xad, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Entity, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xae, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Data.Entity, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
Information | Value |
---|---|
Sequence Length | 549 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x68, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Workflow.Compiler, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x69, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.WSMan.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x6a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.WSMan.Runtime, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x6b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MiguiControls, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x6c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MMCEx, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x6d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MMCFxCommon, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x6e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MSBuild, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x6f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mscorlib, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x70, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x71, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = napcrypt, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x72, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = naphlpr, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x73, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = napinit, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x74, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = napsnap, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x75, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Narrator, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x76, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationBuildTasks, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x77, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationBuildTasks, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x78, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationCFFRasterizer, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x79, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationCore, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x7a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x7b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFontCache, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x7c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x7d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x7e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x7f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemData, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x80, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemDrawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x81, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x82, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework-SystemXmlLinq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x83, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Aero, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x84, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Aero, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x85, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.AeroLite, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x86, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Classic, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x87, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Classic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x88, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Luna, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x89, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Luna, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x8a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Royale, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x8b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationFramework.Royale, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x8c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationUI, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x8d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationUI, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x8e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ReachFramework, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -3 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x8f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ReachFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -3 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x90, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SecurityAuditPoliciesSnapIn, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x91, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SMDiagnostics, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x92, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SMDiagnostics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x93, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SMSvcHost, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x94, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = SrpUxSnapIn, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x95, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x96, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x97, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x98, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Activities.Core.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x99, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Activities.DurableInstancing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x9a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Activities.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x9b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.AddIn, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x9c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.AddIn, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x9d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.AddIn.Contract, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x9e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 110 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x13f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = WindowsFormsIntegration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x140, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = WsatConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x141, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = XamlBuildTask, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 3 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x142, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = XsdBuildTask, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 3 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x100, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x30e130, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 172 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000630, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000630, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000630, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x30e400, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000630, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000630, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000630, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000630, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 13 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x722 |
Start Address | 0xfffff8000271a3ac |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 80 |
Symbol | Parameters |
---|---|
_snwprintf | _Count = 0x72, _Format = %s\%s\%s, _Dest_out = \REGISTRY\MACHINE\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage, ret_val_out = 108 |
Information | Value |
---|---|
Sequence Length | 21 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
_snwprintf | _Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006, ret_val_out = 100 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ret_val_out = 100 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008, ret_val_out = 100 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x8e4 |
Start Address | 0xfffff8000271b2a4 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 24 |
Symbol | Parameters |
---|---|
wcsstr | _Str = \Device\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}, _SubStr = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4} |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x6f8 |
Start Address | 0xfffff800026c5060 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 6 |
Symbol | Parameters |
---|---|
ZwSetValueKey | KeyHandle_unk = 0xffffffff800007d8, ValueName = UpperBind, TitleIndex = 0x0, Type = 0x7, Data = Ndisuio, DataSize = 0x6c, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be8000+0xca8 |
Start Address | 0xfffff8800157fc40 |
Information | Value |
---|---|
Sequence Length | 15 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisRegisterProtocolDriver | ret_val_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9580, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9580, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bea000+0x10b |
Start Address | 0xfffff8800157f880 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
NdisRegisterProtocol | ret_val_out = 0xfffffa80030e9a50 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bea000+0x32b |
Start Address | 0xfffff88001583630 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisDeregisterProtocol | ret_val_out = 0xfffffa80030e9a50 |
Information | Value |
---|---|
Trigger | ndisInitializeBindingEx+0x713 |
Start Address | 0xfffffa8001be8b54 |
Information | Value |
---|---|
Sequence Length | 577 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
wcsncpy | _Source = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, _Count = 0x104, _Dest_out = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, ret_val_out = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4} |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
RtlInitUnicodeString | SourceString = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, DestinationString_out = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4} |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
NdisMGetDeviceProperty | ret_val_out = 0xfffffa8001f5b050 |
IoGetDriverObjectExtension | DriverObject_unk = 0xfffffa8003106060, ClientIdentificationAddress_ptr = 0x4e4d4944, ret_val_ptr_out = 0xfffffa80031aaa10 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2e000 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffff880038f71ac, ret_val_out = 1 |
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 53, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 3d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = be, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = d9, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 74, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff880038f7102, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 53, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 53, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff880038f71ac, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffff880038f7754, ret_val_out = 1 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 3d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = b3, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = f9, ret_val_out = 2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff880038f7702, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff880038f7754, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffff880038f78f8, ret_val_out = 1 |
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 53, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 3d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 13, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = b7, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = d9, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 74, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff880038f7802, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 53, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 53, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff880038f78f8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffff880038f8250, ret_val_out = 1 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 74, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 41, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 56, ret_val_out = 2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff880038f8202, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff880038f8250, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffff880038f781c, ret_val_out = 1 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 74, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 57, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 3d, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = e6, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = b7, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff880038f7802, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff880038f781c, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
MmIsAddressValid | VirtualAddress_ptr = 0xfffff880038f7110, ret_val_out = 1 |
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = bb, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6e, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = cc, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = cc, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = cc, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 53, ret_val_out = 2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0xfffff880038f7102, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = bb, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6e, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = bb, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = 6e, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 |
IoAllocateMdl | VirtualAddress_ptr = 0xfffff880038f7110, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0x0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2e000 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2e000 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c3c700 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2e000 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa8001872ba0 |
NdisOidRequest | ret_val_out = 0x103 |
KeSetEvent | Event_unk = 0xfffffa8001872ba0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001872ba0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8001872ba0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be9000+0x439 |
Start Address | 0xfffff88001580470 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisIMRegisterLayeredMiniport | ret_val_out = 0xc000009a |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x7f4 |
Start Address | 0xfffff800026c4800 |
Information | Value |
---|---|
Sequence Length | 2 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 4 |
Symbol | Parameters |
---|---|
ZwCreateKey | DesiredAccess_unk = 0xf003f, ObjectAttributes_ptr = 0xfffff880022c93e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\System\CurrentControlSet\Services\filter_c06b1a3b, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, TitleIndex = 0x0, Class_ptr = 0x0, CreateOptions = 0x0, KeyHandle_ptr_out = 0xfffff880022c9668, KeyHandle_out = 0xffffffff800007d8, Disposition_ptr_out = 0xfffff880022c9650, Disposition_out = 0x1, ret_val_unk_out = 0x0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030e9a00 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bea000+0xd20 |
Start Address | 0xfffff8800151e9d0 |
Information | Value |
---|---|
Sequence Length | 78 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisFRegisterFilterDriver | ret_val_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a0013d7510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7510, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a0013d7510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7510, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9170, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c90d0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c90e0, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91d0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91d0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001beb000+0x1d5 |
Start Address | 0xfffff8800151c7c0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisFDeregisterFilterDriver | ret_val_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x728 |
Start Address | 0xfffff800026c5b20 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
ZwDeleteKey | KeyHandle_unk = 0xffffffff800001ac, ret_val_unk_out = 0xc0000121 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x8f0 |
Start Address | 0xfffff8000296acbc |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 4 |
Symbol | Parameters |
---|---|
RtlCompareUnicodeString | String1 = \Driver\Psched, String2 = \Driver\NativeWifiP, CaseInsensitive = 0, ret_val_out = 2 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bf4000+0xc0e |
Start Address | 0xfffff880014d6720 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisAllocatePacketPool | ret_val_out = 0xfffffa8002bf7160 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bf4000+0xc32 |
Start Address | 0xfffff880014d6460 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
NdisAllocateBufferPool | ret_val_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be2000+0xbd2 |
Start Address | 0xfffff88001437270 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
GetIfTable2 | ret_val_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x8c6 |
Start Address | 0xfffff800029a8aec |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 36 |
Symbol | Parameters |
---|---|
RtlMultiByteToUnicodeN | MaxBytesInUnicodeString = 0x4c, MultiByteString = {9a399d81-2ead-4f23-bcdd-637fc13dcd51}, BytesInMultiByteString = 0x26, UnicodeString_out = {9a399d81-2ead-4f23-bcdd-637fc13dcd51}, BytesInUnicodeString_ptr_out = 0xfffff880022c9140, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be2000+0xceb |
Start Address | 0xfffff88001423fd0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 2 |
Symbol | Parameters |
---|---|
FreeMibTable | ret_val_out = 0x15083a0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x758 |
Start Address | 0xfffff80002699750 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 8 |
Symbol | Parameters |
---|---|
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | KiSystemServiceExit+0x1a6 |
Start Address | 0xfffffa8001be4659 |
Information | Value |
---|---|
Sequence Length | 573 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
_snwprintf | _Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009, ret_val_out = 100 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010, ret_val_out = 100 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011, ret_val_out = 100 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x77, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties, ret_val_out = 106 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001842780, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a00115e050, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001842780, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{E43D242B-9EAB-4626-A952-46649FBB939A}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0cbf0, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a00115e050, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001842780, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005 |
ZwOpenKey | DesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
wcsncmp | _String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, ret_val_out = 108 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_snwprintf | _Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi, ret_val_out = 104 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
_wcsicmp | _Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = Export, DestinationString_out = Export |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x36, KeyValueInformation_ptr_out = 0xfffff8a001ec2620, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x2a, KeyValueInformation_deref_Data_out = \Device\NdisWanIpv6, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005 |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9220, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = *IfType, DestinationString_out = *IfType |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = *IfType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = *IfType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2e590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2e59c, KeyValueInformation_deref_Data_out = 0x6, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005 |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9220, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = *MediaType, DestinationString_out = *MediaType |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = *MediaType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = *MediaType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2e590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2e59c, KeyValueInformation_deref_Data_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005 |
ZwOpenKey | DesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9220, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
RtlInitUnicodeString | SourceString = *PhysicalMediaType, DestinationString_out = *PhysicalMediaType |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = *PhysicalMediaType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023 |
ZwQueryValueKey | KeyHandle_unk = 0xffffffff800007d4, ValueName = *PhysicalMediaType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2e590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2e59c, KeyValueInformation_deref_Data_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa8002b931f0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
_wcsicmp | _Str1 = \Device\NdisWanIp, _Str2 = \Device\NdisWanBh, ret_val_out = 7 |
_wcsicmp | _Str1 = \Device\NdisWanIp, _Str2 = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, ret_val_out = -13 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
wcsncpy | _Source = \Device\NdisWanBh, _Count = 0x100, _Dest_out = \Device\NdisWanBh, ret_val_out = \Device\NdisWanBh |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
RtlInitUnicodeString | SourceString = \Device\NdisWanBh, DestinationString_out = \Device\NdisWanBh |
NdisOpenAdapter | ret_val_out = 0xfffff8800152e110 |
Information | Value |
---|---|
Trigger | NdisOpenAdapter+0x322 |
Start Address | 0xfffffa8001bf4206 |
Information | Value |
---|---|
Sequence Length | 104 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0 |
NdisRequest | ret_val_out = 0x103 |
KeSetEvent | Event_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0 |
NdisRequest | ret_val_out = 0x103 |
KeSetEvent | Event_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0 |
NdisRequest | ret_val_out = 0x103 |
KeSetEvent | Event_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
wcsncpy | _Source = NdisWanBh, _Count = 0x100, _Dest_out = NdisWanBh, ret_val_out = NdisWanBh |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
_snwprintf | _Count = 0x100, _Format = %S, _Dest_out = NdisWan Adapter, ret_val_out = 15 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
wcsncpy | _Source = NdisWan Adapter, _Count = 0x100, _Dest_out = NdisWan Adapter, ret_val_out = NdisWan Adapter |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
wcsncpy | _Source = \Device\NdisWanIp, _Count = 0x100, _Dest_out = \Device\NdisWanIp, ret_val_out = \Device\NdisWanIp |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
RtlInitUnicodeString | SourceString = \Device\NdisWanIp, DestinationString_out = \Device\NdisWanIp |
NdisOpenAdapter | ret_val_out = 0xfffff8800152e110 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0 |
NdisRequest | ret_val_out = 0x103 |
KeSetEvent | Event_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0 |
NdisRequest | ret_val_out = 0x103 |
KeSetEvent | Event_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0 |
NdisRequest | ret_val_out = 0x103 |
KeSetEvent | Event_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001bf3d2d |
Information | Value |
---|---|
Sequence Length | 402 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
wcsncpy | _Source = NdisWanIp, _Count = 0x100, _Dest_out = NdisWanIp, ret_val_out = NdisWanIp |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
_snwprintf | _Count = 0x100, _Format = %S, _Dest_out = NdisWan Adapter, ret_val_out = 15 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
wcsncpy | _Source = NdisWan Adapter, _Count = 0x100, _Dest_out = NdisWan Adapter, ret_val_out = NdisWan Adapter |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2d800 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0 |
RtlQueryRegistryValues | RelativeTo = 0x1, Path = Tcpip\Parameters, QueryTable_unk = 0xfffffa8001c3a5e0, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c96b0, Object_out = 0xfffff8a0013d7e90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013d7e90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlInitUnicodeString | SourceString = \Device\Nsi, DestinationString_out = \Device\Nsi |
IoGetDeviceObjectPointer | ObjectName = \Device\Nsi, DesiredAccess_unk = 0x0, FileObject_unk_out = 0xfffff880022c99a0, DeviceObject_unk_out = 0xfffffa8001c2e380, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c96b0, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ObfReferenceObject | Object_ptr = 0xfffffa80025607f0, ret_val_ptr_out = 0x3 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa8001c2cee0 |
strncpy | _Source = $NtUninstallQ923283$, _Count = 0x52, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$ |
strncpy | _Source = fixdata.dat, _Count = 0x52, _Dest_out = fixdata.dat, ret_val_out = fixdata.dat |
_snwprintf | _Count = 0x104, _Format = \SystemRoot\%S\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$\fixdata.dat, ret_val_out = 44 |
RtlInitUnicodeString | SourceString = \SystemRoot\$NtUninstallQ923283$\fixdata.dat, DestinationString_out = \SystemRoot\$NtUninstallQ923283$\fixdata.dat |
atoi | _Str = 400, ret_val_out = 400 |
IoCreateFile | DesiredAccess_unk = 0x3, ObjectAttributes_ptr = 0xfffff880022c9540, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$\fixdata.dat, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0xfffff880022c98a0, FileAttributes = 0x80, ShareAccess = 0x0, Disposition = 0x3, CreateOptions = 0x868, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff80000000000, InternalParameters_ptr = 0x0, Options = 0x100 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\$NtUninstallQ923283$\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
_wcsnicmp | _String1 = Windows\$NtUninstallQ923283$\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8760, Object_out = 0xfffffa800279c1c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800279c1c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwSetInformationFile | FileHandle_unk = 0xffffffff800007d4, IoStatusBlock_unk = 0xfffff880022c9578, FileInformation_ptr = 0xfffff880022c9570, Length = 0x8, FileInformationClass_unk = 0xfffff88000000014, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
ZwCreateSection | DesiredAccess_unk = 0x6, ObjectAttributes_ptr = 0xfffff880022c9540, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName_ptr = 0x0, ObjectAttributes_deref_Attributes = 0x0, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, MaximumSize_ptr = 0x0, SectionPageProtection = 0x4, AllocationAttributes = 0x18000000, FileHandle_unk = 0xffffffff800007d4, SectionHandle_ptr_out = 0xfffffa8001c2ce88, SectionHandle_out = 0xffffffff800007e0, ret_val_unk_out = 0x0 |
ZwMapViewOfSection | SectionHandle_unk = 0xffffffff800007e0, ProcessHandle_unk = 0xffffffffffffffff, ZeroBits = 0x0, CommitSize = 0x0, InheritDisposition_unk = 0xfffff88000000002, AllocationType = 0x0, AccessProtection = 0x4, BaseAddress_ptr_out = 0xfffffa8001c2ce98, BaseAddress_out = 0x90000, SectionOffset_out = 0x0, ViewSize_ptr_out = 0xfffff880022c98a8, ViewSize_out = 0x19000000, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | RtlInitUnicodeString+0x52 |
Start Address | 0xfffffa8001bdd5a2 |
Information | Value |
---|---|
Sequence Length | 65 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
IoCreateDevice | DriverObject_unk = 0xfffffa8002513880, DeviceExtensionSize = 0x0, DeviceName = \Device\RawDisk1, DeviceType_unk = 0x7, DeviceCharacteristics = 0x1, Exclusive = 0 |
_wcsnicmp | _String1 = Null, _String2 = netbt, _MaxCount = 0x4, ret_val_out = 16 |
_wcsnicmp | _String1 = Null, _String2 = afd, _MaxCount = 0x4, ret_val_out = 13 |
_wcsnicmp | _String1 = Null, _String2 = Null, _MaxCount = 0x4, ret_val_out = 0 |
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001f03590, ThreadHandle_ptr_out = 0xfffff880022c9830, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 |
ZwWaitForSingleObject | Handle_unk = 0xffffffff800007dc, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff800007dc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffffa80030ddb50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030ddb50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlCreateSecurityDescriptor | Revision = 0x1, SecurityDescriptor_unk_out = 0xfffff880022c9850, ret_val_unk_out = 0x0 |
SeSetSecurityDescriptorInfo | Object_ptr = 0xfffffa8003142620, SecurityInformation_unk = 0xfffff880022c9898, ModificationDescriptor_unk = 0xfffff880022c9850, ObjectsSecurityDescriptor_unk = 0xfffffa8003142730, PoolType_unk = 0x1, GenericMapping_unk = 0xfffff880022c9840, ObjectsSecurityDescriptor_unk_out = 0xfffffa8003142730, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
atoi | _Str = 16, ret_val_out = 16 |
ZwCreateSection | DesiredAccess_unk = 0x6, ObjectAttributes_ptr = 0xfffff880022c98f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName_ptr = 0x0, ObjectAttributes_deref_Attributes = 0x0, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, MaximumSize_ptr = 0xfffffa8001c2ceb0, SectionPageProtection = 0x4, AllocationAttributes = 0x18000000, FileHandle_unk = 0x0, SectionHandle_ptr_out = 0xfffffa8001c2ce90, SectionHandle_out = 0xffffffff800007dc, ret_val_unk_out = 0x0 |
ZwMapViewOfSection | SectionHandle_unk = 0xffffffff800007dc, ProcessHandle_unk = 0xffffffffffffffff, ZeroBits = 0x0, CommitSize = 0x0, InheritDisposition_unk = 0xfffffa8000000002, AllocationType = 0x0, AccessProtection = 0x4, BaseAddress_ptr_out = 0xfffffa8001c2cea0, BaseAddress_out = 0x19090000, SectionOffset_out = 0x0, ViewSize_ptr_out = 0xfffff880022c9a10, ViewSize_out = 0x1000000, ret_val_unk_out = 0x0 |
_snwprintf | _Count = 0x52, _Format = \Device\%S, _Dest_out = \Device\RawDisk2, ret_val_out = 16 |
RtlInitUnicodeString | SourceString = \Device\RawDisk2, DestinationString_out = \Device\RawDisk2 |
IoCreateDevice | DriverObject_unk = 0xfffffa8002513880, DeviceExtensionSize = 0x0, DeviceName = \Device\RawDisk2, DeviceType_unk = 0x7, DeviceCharacteristics = 0x1, Exclusive = 0 |
_wcsnicmp | _String1 = Null, _String2 = netbt, _MaxCount = 0x4, ret_val_out = 16 |
_wcsnicmp | _String1 = Null, _String2 = afd, _MaxCount = 0x4, ret_val_out = 13 |
_wcsnicmp | _String1 = Null, _String2 = Null, _MaxCount = 0x4, ret_val_out = 0 |
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a0005df400, ThreadHandle_ptr_out = 0xfffff880022c9830, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 |
ZwWaitForSingleObject | Handle_unk = 0xffffffff80000804, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
ZwClose | Handle_unk = 0xffffffff80000804, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000804, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffffa800310aad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800310aad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
RtlCreateSecurityDescriptor | Revision = 0x1, SecurityDescriptor_unk_out = 0xfffff880022c9850, ret_val_unk_out = 0x0 |
SeSetSecurityDescriptorInfo | Object_ptr = 0xfffffa8002fb9d80, SecurityInformation_unk = 0xfffff880022c9898, ModificationDescriptor_unk = 0xfffff880022c9850, ObjectsSecurityDescriptor_unk = 0xfffffa8002fb9e90, PoolType_unk = 0x1, GenericMapping_unk = 0xfffff880022c9840, ObjectsSecurityDescriptor_unk_out = 0xfffffa8002fb9e90, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a0005df400, ThreadHandle_ptr_out = 0xfffffa8001c2cef8, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Trigger | PspSystemThreadStartup+0x57 |
Start Address | 0xfffffa8001bc88f4 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 3 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002f81b50 |
rand | ret_val_out = 17888 |
PsTerminateSystemThread | ExitStatus_unk = 0x0 |
Information | Value |
---|---|
Sequence Length | 2199 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa80030e9a00 | ||||
rand | ret_val_out = 12425 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
PsCreateSystemThread | DesiredAccess = 0x0, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bdfef4, StartContext_ptr = 0xfffffa8001c2d8d0, ThreadHandle_ptr_out = 0xfffff880022c9b48, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ZwWaitForSingleObject | Handle_unk = 0xffffffff800007f4, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ZwClose | Handle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 | ||||
strncpy | _Source = System, _Count = 0x11, _Dest_out = System, ret_val_out = System | ||||
RtlInitUnicodeString | SourceString = \Device\Null, DestinationString_out = \Device\Null | ||||
IoGetDeviceObjectPointer | ObjectName = \Device\Null, DesiredAccess_unk = 0x0, FileObject_unk_out = 0xfffff880022c9b40, DeviceObject_unk_out = 0xfffffa8001c2c540, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002516740, ret_val_ptr_out = 0x3 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002db2820 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002f64ce0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8003062510 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002e55aa0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8002f7f7b0 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa800303a160 | ||||
KeInitializeMutex | Level = 0x0, Mutex_unk_out = 0xfffffa8003133510 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4720, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 13, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b56000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b56000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff8000299db02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff8000299db60, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4aa0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b57000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b57000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002986d02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002986df0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4800, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2e, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b58000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b58000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002982802, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002982820, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c6de0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 09, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b59000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b59000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002b4f402, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002b4f440, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4520, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 31, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 03, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5a000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5a000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029b7f02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029b7f80, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4b20, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 33, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5b000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5b000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029d9c02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f3, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029d9cdc, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4780, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 7d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 16, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5c000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5c000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029e0702, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 20, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029e0780, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c4640, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bd, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 30, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 0c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5d000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5d000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029c5702, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 08, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029c5740, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800026c49e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c4, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = fa, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ec, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 9c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 10, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 48, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 29, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5e000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5e000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff80002987d02, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 89, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 18, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002987d14, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0xfffff800029ca602, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = dc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 55, ret_val_out = 2 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff800029ca650, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KfRaiseIrql | NewIrql_unk = 0x2, ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0x0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
ZwOpenEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0xc0000034 | ||||
_snwprintf | _Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk1, ret_val_out = 16 | ||||
_snwprintf | _Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk2, ret_val_out = 16 | ||||
_snprintf | _Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par1, ret_val_out = 8 | ||||
_swprintf | _Format = %S, _Dest_out = \??\Par1, ret_val_out = 8 | ||||
_snprintf | _Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par2, ret_val_out = 8 | ||||
_swprintf | _Format = %S, _Dest_out = \??\Par2, ret_val_out = 8 | ||||
_snwprintf | _Count = 0x104, _Format = \BaseNamedObjects\%S, _Dest_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, ret_val_out = 62 | ||||
RtlInitUnicodeString | SourceString = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, DestinationString_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153} | ||||
ZwOpenEvent | DesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0x0 | ||||
ZwClose | Handle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9560, Object_out = 0xfffffa8002dd1890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002dd1890, ret_val_ptr_out = 0x5 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
RtlQueryRegistryValues | RelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff880022c9970, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9660, Object_out = 0xfffff8a0013e0c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0013e0c50, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
RtlNtStatusToDosError | Status_unk = 0x0, ret_val_out = 0x0 | ||||
RtlInitUnicodeString | SourceString = \SystemRoot, DestinationString_out = \SystemRoot | ||||
ZwOpenSymbolicLinkObject | DesiredAccess_unk = 0x1, ObjectAttributes_unk = 0xfffff880022c96d0, SymbolicLinkHandle_ptr_out = 0xfffff880022c99a0, ret_val_unk_out = 0x0 | ||||
ZwQuerySymbolicLinkObject | SymLinkObjHandle_unk = 0xffffffff800007f4, LinkTarget_out = \Device\Harddisk0\Partition2\Windows, DataWritten_ptr_out = 0x0, ret_val_unk_out = 0x0 | ||||
wcsncpy | _Source = Windows, _Count = 0x104, _Dest_out = Windows, ret_val_out = Windows | ||||
strncpy | _Source = $NtUninstallQ923283$, _Count = 0x52, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$ | ||||
_snwprintf | _Count = 0x51, _Format = %S, _Dest_out = $NtUninstallQ923283$, ret_val_out = 20 | ||||
_snwprintf | _Count = 0x103, _Format = \SystemRoot\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$, ret_val_out = 32 | ||||
RtlInitUnicodeString | SourceString = \SystemRoot\$NtUninstallQ923283$, DestinationString_out = \SystemRoot\$NtUninstallQ923283$ | ||||
ZwOpenFile | DesiredAccess_unk = 0x100000, ObjectAttributes_ptr = 0xfffff880022c96d0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$, ObjectAttributes_deref_Attributes = 0x240, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, ShareAccess = 0x7, OpenOptions = 0x21, FileHandle_ptr_out = 0xfffff880022c99a0, FileHandle_out = 0xffffffff80000824, IoStatusBlock_unk_out = 0xfffff880022c9700, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c99a8, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa800202b650, ret_val_ptr_out = 0xa | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002c55030, ret_val_ptr_out = 0x2 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
ZwClose | Handle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9490, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeInitializeEvent | Type_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80026b7660 | ||||
PsCreateSystemThread | DesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001ecfc00, ThreadHandle_ptr_out = 0xfffffa8001c2c210, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000004 | ||||
ZwQuerySystemInformation | SystemInformationClass_unk = 0xb, Length_ptr = 0x9530, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80030e9a00 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x779a17b0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b5f000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d0, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1d, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ed, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 5f, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = ff, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 49, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = c1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e2, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 05, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = bc, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 1a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 40, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = e9, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 2a, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000b5f000, MemoryDescriptorList_unk = 0xfffffa8002e516c0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x779a17e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = d1, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = b8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 50, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 00, ret_val_out = 2 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b60000 | ||||
sprintf | _Format = %02x, _Dest_out = 8b, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 44, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 24, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 28, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 83, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = f8, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 01, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 77, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 6c, ret_val_out = 2 | ||||
sprintf | _Format = %02x, _Dest_out = 4c, ret_val_out = 2 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 38 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa800311f640 |
rand | ret_val_out = 25331 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102 |
RtlNtStatusToDosError | Status_unk = 0x102, ret_val_out = 0x5b4 |
KeAcquireSpinLockRaiseToDpc | SpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0 |
PsGetCurrentThreadId | ret_val_unk_out = 0x1a8 |
KeReleaseSpinLock | SpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0 |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002fc83c0 |
rand | ret_val_out = 11502 |
KeWaitForSingleObject | Object_ptr = 0xfffffa80031273d0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0 |
Information | Value |
---|---|
Sequence Length | 82 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8003177620 |
rand | ret_val_out = 5970 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001b865b8, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001b86598 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
RtlInitAnsiString | DestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0 |
RtlAnsiStringToUnicodeString | DestinationString_ptr = 0xfffff8a001820b78, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001820b88, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001820b68 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
RtlInitAnsiString | DestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0 |
RtlAnsiStringToUnicodeString | DestinationString_ptr = 0xfffff8a001e9a708, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
IoCreateFile | DesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001e9a718, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
RtlNtStatusToDosError | Status_unk = 0xc0000034, ret_val_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0 |
RtlFreeAnsiString | AnsiString_ptr = 0xfffff8a001e9a6f8 |
RtlFreeAnsiString | AnsiString = \ |
KeReleaseMutex | Mutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0 |
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000 |
Information | Value |
---|---|
Sequence Length | 1613 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
KeGetCurrentThread | ret_val_out = 0xfffffa8002e72880 | ||||
rand | ret_val_out = 14463 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800435e000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800437b000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002ff5cd8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e64000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9c000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9d000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ec9000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eca000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecb000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecc000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecd000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ece000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecf000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed0000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed1000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed2000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed3000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed4000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed5000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed6000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed7000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed8000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed9000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eda000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edb000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edc000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edd000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ede000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edf000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee0000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee1000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa8002f1d010, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee3000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eec000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x3293e00, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x3293000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0xc0000054 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b93000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b97000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x94000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x94000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9b000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9c000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9d000 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9e000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9f000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000bb0000 | ||||
ZwFlushVirtualMemory | ProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0xc88fe00, RegionSize_ptr = 0xfffff880045bbb58 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
IofCompleteRequest | Irp_unk = 0xfffffa80032272d0, PriorityBoost = 0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
ExInterlockedRemoveHeadList | ListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f18c78 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa8001ae4000, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88004800000 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x4 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Trigger | PspSystemThreadStartup+0x57 |
Start Address | 0xfffffa8001bdfef4 |
Information | Value |
---|---|
Sequence Length | 739 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa80018b0040 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 91 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = HH , _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 101 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -107 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 106 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 107 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = 99 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -105 |
_strnicmp | _Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -3 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -25 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = -27 |
_strnicmp | _Str1 = System, _Str2 = 4h, _MaxCount = 0x6, ret_val_out = 63 |
_strnicmp | _Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 103 |
_strnicmp | _Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 11 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -90 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -97 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -88 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -110 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -94 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -69 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -105 |
_strnicmp | _Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -3 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -98 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -20 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = /, _MaxCount = 0x6, ret_val_out = 68 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -70 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -18 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -77 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = -93 |
_strnicmp | _Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = 8 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 90 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = 8 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 97 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -28 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = -125 |
_strnicmp | _Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = 19 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -139 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -29 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -87 |
_strnicmp | _Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -4 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115 |
_strnicmp | _Str1 = System, _Str2 = System, _MaxCount = 0x6, ret_val_out = 0 |
PsTerminateSystemThread | ExitStatus_unk = 0x0 |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001c02015 |
Information | Value |
---|---|
Sequence Length | 251 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Program Files (x86)\Google\Update\GoogleUpdate.exe, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80031f6701 |
ProbeForRead | Address_ptr = 0x49e040, Length_ptr = 0x8, Alignment = 0x1 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x264, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880044dd9e0, ret_val_unk_out = 0x0 |
ZwQueryInformationProcess | ProcessHandle_unk = 0xffffffff80000804, ProcessInformationClass_unk = 0x0, ProcessInformationLength = 0x30, ProcessInformation_ptr_out = 0xfffff880044dd9f0, ReturnLength_ptr_out = 0x0, ret_val_unk_out = 0x0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
PsLookupProcessByProcessId | ProcessId_unk = 0x3e8, Process_unk_out = 0xfffff880044dd818, ret_val_unk_out = 0x0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x104, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
ObfDereferenceObject | Object_ptr = 0xfffffa800251c060, ret_val_ptr_out = 0x4 |
_stricmp | _Str1 = GoogleUpdate.e, _Str2 = svchost.exe, ret_val_out = -12 |
ZwClose | Handle_unk = 0xffffffff80000804, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000804, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd750, Object_out = 0xfffffa800251c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800251c060, ret_val_ptr_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76405038, Length_ptr = 0x9c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x270, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x8 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76400e00, Length_ptr = 0x84, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76400e98, Length_ptr = 0xa6, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0x96, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000804, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd830, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x270, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x7 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e940, Length_ptr = 0x88, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x76408b64, Length_ptr = 0x2a, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e940, Length_ptr = 0x2e, Alignment = 0x2 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x49e9c0, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\apphelp.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\apphelp.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x49e9c0, Length_ptr = 0x46, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\SysWOW64\apphelp.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = SysWOW64\apphelp.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x29c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001bcd970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001bcd970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e5c8, Length_ptr = 0x40, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\AppPatch\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = AppPatch\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 61 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 61 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 127 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15c6760, Length_ptr = 0x9a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 21 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x15c |
Information | Value |
---|---|
Sequence Length | 14 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x15c |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 70 |
Process | Amount |
---|---|
Process 15 (svchost.exe, PID: 836) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdfb8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x21fe000, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 561 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f9db60 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f9db60, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5b00, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002ecfe00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002ecfe00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4d5b00, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
Information | Value |
---|---|
Trigger | ExGetPreviousMode+0xf |
Start Address | 0xfffffa8001bcd573 |
Information | Value |
---|---|
Sequence Length | 357 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
IoAllocateMdl | VirtualAddress_ptr = 0x189e598, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0 |
ExGetPreviousMode | ret_val_unk_out = 0xfffffa80031f6701 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0 |
IoFreeMdl | Mdl_unk = 0xfffffa8002e516c0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000804, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd830, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x29c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001bcd970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001bcd970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x563888, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00136efa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00136efa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189eb9c, Length_ptr = 0x40, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\AppPatch\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = AppPatch\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 61 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x29c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001bcd970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001bcd970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ProbeForRead | Address_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x189e7fc, Length_ptr = 0x40, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
_wcsnicmp | _String1 = Windows\AppPatch\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0 |
_wcsnicmp | _String1 = AppPatch\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 61 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x29c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001bcd970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001bcd970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x268, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x26c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a0012b1a50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0012b1a50, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x264, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa800251c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800251c060, ret_val_ptr_out = 0x6 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003138810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003138810, ret_val_ptr_out = 0x3 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x25c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec26c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ec26c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x24c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x250, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x254, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x26c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa800251c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800251c060, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
PsGetCurrentProcess | ret_val_out = 0xfffffa80031529e0 |
strncpy | _Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
_strnicmp | _Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Trigger | _snwprintf+0xd2 |
Start Address | 0xfffffa8001bdf40e |
Information | Value |
---|---|
Sequence Length | 132 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
wcsncpy | _Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system |
RtlInitUnicodeString | SourceString = \??\Par1\system, DestinationString_out = \??\Par1\system |
IoCreateFile | DesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a0003074bf, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000034 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002ff5cd8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002ff5cd8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
_wcsnicmp | _String1 = FltMgr, _String2 = netbt, _MaxCount = 0x6, ret_val_out = -8 |
_wcsnicmp | _String1 = FltMgr, _String2 = afd, _MaxCount = 0x6, ret_val_out = 5 |
_wcsnicmp | _String1 = FltMgr, _String2 = Null, _MaxCount = 0x6, ret_val_out = -8 |
_wcsnicmp | _String1 = FltMgr, _String2 = Beep, _MaxCount = 0x6, ret_val_out = 4 |
_wcsnicmp | _String1 = FltMgr, _String2 = tcpip, _MaxCount = 0x6, ret_val_out = -14 |
_wcsnicmp | _String1 = FltMgr, _String2 = Nsiproxy, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
_wcsnicmp | _String1 = fastfat, _String2 = netbt, _MaxCount = 0x7, ret_val_out = -8 |
_wcsnicmp | _String1 = fastfat, _String2 = afd, _MaxCount = 0x7, ret_val_out = 5 |
_wcsnicmp | _String1 = fastfat, _String2 = Null, _MaxCount = 0x7, ret_val_out = -8 |
_wcsnicmp | _String1 = fastfat, _String2 = Beep, _MaxCount = 0x7, ret_val_out = 4 |
_wcsnicmp | _String1 = fastfat, _String2 = tcpip, _MaxCount = 0x7, ret_val_out = -14 |
_wcsnicmp | _String1 = fastfat, _String2 = Nsiproxy, _MaxCount = 0x7, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
IofCompleteRequest | Irp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001be0000+0x2 |
Start Address | 0xfffff800026de1d0 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 11 (svchost.exe, PID: 564) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa8002d8ab30 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x830 |
Start Address | 0xfffff800026c3220 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 11 (svchost.exe, PID: 564) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c14000+0x812 |
Start Address | 0xfffff8000265b458 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 11 (svchost.exe, PID: 564) | 2 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001bc9748 |
Information | Value |
---|---|
Sequence Length | 494 |
Process | Amount |
---|---|
Process 34 (googleupdate.exe, PID: 2220) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x74a3f0, Length_ptr = 0x2a, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x7 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x737b58, Length_ptr = 0x2a, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x737b58, Length_ptr = 0x2a, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x737b58, Length_ptr = 0x2a, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x737b58, Length_ptr = 0x2a, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 110 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xff93f0, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 117 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x104d710, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 420 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a88f0, Length_ptr = 0xd2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16960b0, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1696630, Length_ptr = 0x9e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaf138, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xcaf548, Length_ptr = 0x96, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 1203 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000badac0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000badac0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000baeac0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000baeac0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bafac0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bafac0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb1ac0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb1ac0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb2ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb2ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb3ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb3ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb4ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb4ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb5ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb5ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb6ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb6ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb7ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb7ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb8ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb8ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb9ad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bb9ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbaad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bbaad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbbad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bbbad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbcad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bbcad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbdad0 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bbdad0, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 | ||||
IoAllocateMdl | VirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0 | ||||
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbeb60 | ||||
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88000bbeb60, MemoryDescriptorList_unk = 0xfffffa80027896b0 | ||||
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0 | ||||
IoFreeMdl | Mdl_unk = 0xfffffa80027896b0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
ProbeForRead | Address_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
ProbeForRead | Address_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4 | ||||
ProbeForRead | Address_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x108 | ||||
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 | ||||
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 | ||||
ObReferenceObjectByHandle | Handle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 | ||||
ObfDereferenceObject | Object_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Sequence Length | 502 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001bfb5b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001bfb5b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x158acf0, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001bfb5b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001bfb5b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x158aae0, Length_ptr = 0x9e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001bfb5b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001bfb5b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x166c2d0, Length_ptr = 0x102, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001bfb5b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001bfb5b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16bb140, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001be0667 |
Information | Value |
---|---|
Sequence Length | 107 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x8ac |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x13 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 116 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ExInterlockedInsertTailList | ListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0 |
KeSetEvent | Event_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 216 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x36e000, Length_ptr = 0xea, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 43 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 277 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x150fb60, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14d9790, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 169 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1696790, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 369 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x397700, Length_ptr = 0x108, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3e2f00, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 238 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf8bc80, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1049910, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 130 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15c8750, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 23 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
ProbeForRead | Address_ptr = 0x132f358, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 28 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002ed2f20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002ed2f20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002ecfe00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002ecfe00, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
Information | Value |
---|---|
Sequence Length | 433 |
Process | Amount |
---|---|
Process 15 (svchost.exe, PID: 836) | 1 |
Symbol | Parameters |
---|---|
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdba8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e624a0, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdfb8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x21fe000, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdba8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x2e624a0, Length_ptr = 0x4c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fdfb8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x21fe000, Length_ptr = 0x74, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe130, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3e130 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f3e130, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe130, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3f130 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f3f130, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe130, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f50130 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f50130, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe130, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f51130 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f51130, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f52140 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f52140, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f53140 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f53140, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f54140 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f54140, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f55140 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f55140, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f56140 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f56140, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f57140 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f57140, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f58140 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f58140, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f59140 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f59140, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x21fe238, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
ProbeForRead | Address_ptr = 0x21fe098, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x263ee00, Length_ptr = 0x5e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
ObfReferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002edb290 |
IoAllocateMdl | VirtualAddress_ptr = 0x21fdef0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f5aef0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007f5aef0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x344 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001bdc000+0xa24 |
Start Address | 0xfffff800029412b8 |
Information | Value |
---|---|
Sequence Length | 1 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 2 |
Process 18 (svchost.exe, PID: 264) | 6 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x8e2a8, Length_ptr = 0x30, Alignment = 0x4 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c02000+0x70 |
Start Address | 0xfffff8000299d04c |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828) | 1 |
Process 39 (googlecrashhandler.exe, PID: 2460) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x8e2a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x18e894, Length_ptr = 0x9a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0xb0c |
ProbeForRead | Address_ptr = 0x8e2a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x18e894, Length_ptr = 0x8c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0xb0c |
Information | Value |
---|---|
Trigger | ObReferenceObjectByHandle+0x29 |
Start Address | 0xfffffa8001bc9b5e |
Information | Value |
---|---|
Sequence Length | 190 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35c300, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 254 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38bab0, Length_ptr = 0xd2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x38bd50, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 3 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 18 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 63 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 15 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 290 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37d650, Length_ptr = 0x14a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf80210, Length_ptr = 0xf8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 215 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc2bb0, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfdf820, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f007d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 66 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 112 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 30 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 127 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1652e80, Length_ptr = 0xbc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce9bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce9bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 282 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xff6cc0, Length_ptr = 0x92, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160af80, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 225 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfae520, Length_ptr = 0xa2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f7030, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 278 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf95880, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f7a30, Length_ptr = 0xec, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 463 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32f3d0, Length_ptr = 0x76, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15cd2c0, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15ccc00, Length_ptr = 0x7c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000630, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000630, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000630, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000630, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16bb5a0, Length_ptr = 0xd6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000630, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 178 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e483c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e483c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14c4b10, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e483c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e483c0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | KiInterruptDispatch+0x34b |
Start Address | 0xfffffa8001bc9793 |
Information | Value |
---|---|
Sequence Length | 152 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x35c680, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 26 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
Information | Value |
---|---|
Sequence Length | 33 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 138 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x160c140, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 257 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x33ccb0, Length_ptr = 0xca, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x33ce70, Length_ptr = 0xce, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 163 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15742e0, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 380 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1581b70, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15c8000, Length_ptr = 0xc2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15c8410, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001bcc813 |
Information | Value |
---|---|
Sequence Length | 99 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x30ee50, Length_ptr = 0xda, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001cd8201, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 51 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
Information | Value |
---|---|
Sequence Length | 230 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1560e40, Length_ptr = 0xdc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 229 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3a3f00, Length_ptr = 0xa6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 38 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | ObfDereferenceObject+0x57 |
Start Address | 0xfffffa8001bc9ba9 |
Information | Value |
---|---|
Sequence Length | 158 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x37b880, Length_ptr = 0xfc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x36de00, Length_ptr = 0xea, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 189 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1543de0, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 273 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x157c240, Length_ptr = 0xb8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1575320, Length_ptr = 0xb2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 171 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1687df0, Length_ptr = 0x7a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16884b0, Length_ptr = 0x7c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
Information | Value |
---|---|
Sequence Length | 277 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf67780, Length_ptr = 0x152, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x154b000, Length_ptr = 0x13c, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001bcc465 |
Information | Value |
---|---|
Sequence Length | 34 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 125 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfc38d0, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 86 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 130 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 145 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1046a40, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 128 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14aa4e0, Length_ptr = 0xd6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 122 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 168 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1616270, Length_ptr = 0xfc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 122 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3812a0, Length_ptr = 0xfe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800006dc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800006dc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800006dc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800006dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800006dc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800006dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | __ascii_strnicmp+0x43 |
Start Address | 0xfffffa8001bcc633 |
Information | Value |
---|---|
Sequence Length | 75 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 81 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 158 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14d8c50, Length_ptr = 0xde, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 189 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x150f560, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
Information | Value |
---|---|
Sequence Length | 47 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 125 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehexthost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiActivScp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiBmlDataCarousel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiExtens, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiiTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiProxy, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiTVMSMusic, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiUPnP, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiUserXp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiVidCtl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiwmp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehiWUapi, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = ehRecObj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16 |
Information | Value |
---|---|
Sequence Length | 94 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 103 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 116 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f6030, Length_ptr = 0xf4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 132 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfb08e0, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 67 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 23 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | PsGetCurrentProcess+0xd |
Start Address | 0xfffffa8001be0008 |
Information | Value |
---|---|
Sequence Length | 25 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 228 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144d920, Length_ptr = 0xf4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 125 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14d95b0, Length_ptr = 0xe0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 208 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32f150, Length_ptr = 0x76, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 280 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x3570d0, Length_ptr = 0xf8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x384310, Length_ptr = 0x130, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 362 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1555e60, Length_ptr = 0xf8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x161ebf0, Length_ptr = 0xc0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 60 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 255 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f05a10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05a10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16bcaa0, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f05a10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f05a10, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x16bcc60, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
Information | Value |
---|---|
Trigger | KeReleaseMutant+0x17c |
Start Address | 0xfffffa8001bc96fa |
Information | Value |
---|---|
Sequence Length | 35 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 313 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x144ca20, Length_ptr = 0xf6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1466b80, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 75 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14d9010, Length_ptr = 0xe6, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
Information | Value |
---|---|
Sequence Length | 164 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1625250, Length_ptr = 0xc4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 118 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x334cc0, Length_ptr = 0xdc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 352 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1503f10, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1606460, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001a8bb01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x165a0e0, Length_ptr = 0xd0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 213 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x161e230, Length_ptr = 0xbe, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 134 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1441f50, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | KiSystemServiceExit+0x1a6 |
Start Address | 0xfffffa8001bc9ccf |
Information | Value |
---|---|
Sequence Length | 39 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 2 |
Symbol | Parameters |
---|---|
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | KiSystemServiceExit+0x1a6 |
Start Address | 0xfffffa8001bca13d |
Information | Value |
---|---|
Sequence Length | 80 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 276 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x15a8490, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 521 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
wcsncmp | _String1 = Microsoft.MediaCenter.TV.Tuners.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x47, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.MediaCenter.UI, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x48, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Diagnostics, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x49, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x4a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.PowerShell.Commands.Utility, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x4b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.PowerShell.ConsoleHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x4c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.PowerShell.Editor, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x4d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.PowerShell.GPowerShell, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x4e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.PowerShell.GraphicalHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x4f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.PowerShell.Security, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x50, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x51, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x52, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x53, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x54, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x55, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x56, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x57, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Transactions.Bridge, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x58, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Transactions.Bridge.Dtc, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x59, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Transactions.Bridge.Dtc, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x5a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x5b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.VisualBasic, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x5c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.VisualBasic.Activities.Compiler, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x5d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.VisualBasic.Compatibility, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x5e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.VisualBasic.Compatibility.Data, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x5f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.VisualC, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x60, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.VisualC, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x61, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Windows.Diagnosis.Commands.GetDiagInput, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x62, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x63, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x64, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x65, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Windows.Diagnosis.SDEngine, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x66, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Windows.Diagnosis.SDHost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x67, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Windows.Diagnosis.TroubleshootingPack, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x68, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.Workflow.Compiler, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x69, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.WSMan.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x6a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Microsoft.WSMan.Runtime, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x6b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MiguiControls, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x6c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MMCEx, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x6d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MMCFxCommon, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x6e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = MSBuild, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x6f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mscorlib, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x70, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x71, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = napcrypt, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x72, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = naphlpr, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x73, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = napinit, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x74, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = napsnap, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x75, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = Narrator, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x76, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationBuildTasks, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x77, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationBuildTasks, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x78, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationCFFRasterizer, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x79, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationCore, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x7a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = PresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5 |
Information | Value |
---|---|
Sequence Length | 576 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
wcsncmp | _String1 = System.Web.Extensions.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x113, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Extensions.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x114, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Mobile, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x115, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Mobile, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x116, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.RegularExpressions, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x117, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.RegularExpressions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x118, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Routing, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x119, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Routing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x11a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Services, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x11b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Web.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x11c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Windows.Controls.Ribbon, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x11d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Windows.Forms, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x11e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x11f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Windows.Forms.DataVisualization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x120, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Windows.Forms.DataVisualization.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x121, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Windows.Input.Manipulations, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x122, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Windows.Presentation, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x123, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Windows.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x124, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Workflow.Activities, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x125, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Workflow.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x126, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Workflow.ComponentModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x127, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Workflow.ComponentModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x128, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Workflow.Runtime, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x129, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Workflow.Runtime, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x12a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.WorkflowServices, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x12b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.WorkflowServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x12c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x12d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Xaml.Hosting, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x12e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Xml, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x12f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x130, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Xml.Linq, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x131, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Xml.Linq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x132, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Xml.Serialization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x133, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = TaskScheduler, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -1 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x134, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = UIAutomationClient, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x135, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = UIAutomationClient, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x136, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = UIAutomationClientsideProviders, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x137, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = UIAutomationClientsideProviders, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x138, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = UIAutomationProvider, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x139, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = UIAutomationProvider, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x13a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = UIAutomationTypes, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x13b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = UIAutomationTypes, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x13c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = WindowsBase, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x13d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = WindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x13e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = WindowsFormsIntegration, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x13f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = WindowsFormsIntegration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x140, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = WsatConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x141, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = XamlBuildTask, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 3 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x142, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = XsdBuildTask, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 3 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x100, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x30f120, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 44 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 204 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfa22c0, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 1601 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters | ||||
---|---|---|---|---|---|
wcsncmp | _String1 = System.AddIn.Contract, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x9f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ComponentModel.Composition, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ComponentModel.Composition.Registration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ComponentModel.DataAnnotations, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ComponentModel.DataAnnotations, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Configuration, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Configuration.Install, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Configuration.Install, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Core, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xa9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xaa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xab, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.DataSetExtensions, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xac, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.DataSetExtensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xad, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Entity, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xae, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Entity, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xaf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Entity.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Entity.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Linq, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Linq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.OracleClient, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.OracleClient, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Services, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Services.Client, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Services.Client, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xb9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Services.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xba, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.Services.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xbb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.SqlXml, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xbc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Data.SqlXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xbd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Deployment, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xbe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Deployment, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xbf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Design, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Device, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.DirectoryServices, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.DirectoryServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.DirectoryServices.AccountManagement, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.DirectoryServices.AccountManagement, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.DirectoryServices.Protocols, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.DirectoryServices.Protocols, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Drawing, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xc9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xca, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Drawing.Design, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xcb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Drawing.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xcc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Dynamic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xcd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.EnterpriseServices, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xce, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.EnterpriseServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xcf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IdentityModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IdentityModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IdentityModel.Selectors, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IdentityModel.Selectors, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IdentityModel.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IO.Compression, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IO.Compression.FileSystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IO.Log, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.IO.Log, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Management, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xd9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Management.Automation, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xda, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Management.Instrumentation, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xdb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Management.Instrumentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xdc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Messaging, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xdd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Messaging, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xde, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Net, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xdf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Net, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Net.Http, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Net.Http.WebRequest, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Numerics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Printing, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Printing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Reflection.Context, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Runtime.Caching, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Runtime.DurableInstancing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Runtime.Remoting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xe9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Runtime.Remoting, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xea, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Runtime.Serialization, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xeb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Runtime.Serialization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xec, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Runtime.Serialization.Formatters.Soap, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xed, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Runtime.Serialization.Formatters.Soap, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xee, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Security, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xef, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Security, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.Activation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.Channels, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.Discovery, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.Internals, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.Routing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.ServiceMoniker40, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xf9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.Web, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xfa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceModel.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xfb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceProcess, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xfc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.ServiceProcess, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xfd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Speech, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xfe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Speech, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0xff, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Transactions, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x100, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Transactions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x101, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
wcsncmp | _String1 = System.Web, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 | ||||
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x102, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 | ||||
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec | ||||
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 | ||||
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 | ||||
KeGetCurrentIrql | ret_val_unk_out = 0x0 | ||||
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 | ||||
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 | ||||
For performance reasons the remaining entries are omitted. Click to download all entries as text file. |
Information | Value |
---|---|
Trigger | KiInterruptDispatch+0x34b |
Start Address | 0xfffffa8001bc9993 |
Information | Value |
---|---|
Sequence Length | 42 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 156 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14f8430, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd2bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd2bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001bc99de |
Information | Value |
---|---|
Sequence Length | 229 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1477010, Length_ptr = 0xa2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | __ascii_strnicmp+0x43 |
Start Address | 0xfffffa8001bcc64d |
Information | Value |
---|---|
Sequence Length | 273 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14d87a0, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14dbb70, Length_ptr = 0xaa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a79010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 131 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1612200, Length_ptr = 0xa8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa9bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 234 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.EnterpriseServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xcf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IdentityModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IdentityModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IdentityModel.Selectors, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IdentityModel.Selectors, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IdentityModel.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IO.Compression, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IO.Compression.FileSystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IO.Log, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.IO.Log, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Management, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xd9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Management.Automation, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xda, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Management.Instrumentation, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xdb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Management.Instrumentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xdc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Messaging, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xdd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Messaging, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xde, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Net, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xdf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Net, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Net.Http, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Net.Http.WebRequest, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Numerics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Printing, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Printing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0xe5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = System.Reflection.Context, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2 |
Information | Value |
---|---|
Sequence Length | 214 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x30e9a0, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 27 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001bdca2a |
Information | Value |
---|---|
Sequence Length | 153 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x1512410, Length_ptr = 0xbc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14d93d0, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
Information | Value |
---|---|
Sequence Length | 162 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x162f3a0, Length_ptr = 0x9a, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 365 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x14f6c30, Length_ptr = 0xf4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1620230, Length_ptr = 0xbc, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001a6b401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x1049730, Length_ptr = 0xe2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce0450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce0450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Sequence Length | 45 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | PsGetCurrentProcessId+0x10 |
Start Address | 0xfffffa8001bc9696 |
Information | Value |
---|---|
Sequence Length | 215 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x14da4b0, Length_ptr = 0xd8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x155c020, Length_ptr = 0xa0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f237d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f237d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1 |
Information | Value |
---|---|
Sequence Length | 161 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xfa6d60, Length_ptr = 0xa4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | KiInterruptDispatchNoLock+0x335 |
Start Address | 0xfffffa8001bca065 |
Information | Value |
---|---|
Sequence Length | 516 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x368930, Length_ptr = 0xe8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x368b30, Length_ptr = 0xf2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x368d30, Length_ptr = 0xf0, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x34c840, Length_ptr = 0xfa, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Sequence Length | 192 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0xf95b20, Length_ptr = 0xd4, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwDuplicateObject | SourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0 |
ZwQueryKey | KeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Sequence Length | 71 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37 |
ZwEnumerateKey | KeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
wcsncmp | _String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
Information | Value |
---|---|
Trigger | wcsncmp+0x2f |
Start Address | 0xfffffa8001bc9da9 |
Information | Value |
---|---|
Sequence Length | 79 |
Process | Amount |
---|---|
Process 33 (mscorsvw.exe, PID: 2028) | 1 |
Symbol | Parameters |
---|---|
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ZwClose | Handle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ef7b01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
ProbeForRead | Address_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x7ec |
PsGetCurrentProcess | ret_val_out = 0xfffffa80018fab30 |
strncpy | _Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
_strnicmp | _Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2cb00 |
ObReferenceObjectByHandle | Handle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
Information | Value |
---|---|
Trigger | KeLowerIrql+0x7 |
Start Address | 0xfffffa8001be06bb |
Information | Value |
---|---|
Sequence Length | 9 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c02000+0x70 |
Start Address | 0xfffff88002d558a5 |
Information | Value |
---|---|
Sequence Length | 798 |
Process | Amount |
---|---|
Process 2 (System, PID: 4) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000045c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000454, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000044c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000444, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000043c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000434, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000042c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000424, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000041c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000414, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000040c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000404, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003f0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000734, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000730, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000073c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000744, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000074c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000754, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000075c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000764, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff8000076c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000660, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800006e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000758, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000770, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000774, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000760, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000768, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000750, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000748, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000740, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000738, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000724, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff800003fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000408, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000418, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000420, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000428, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x4 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x9cc |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x9cc |
Information | Value |
---|---|
Trigger | PsGetCurrentProcess+0xd |
Start Address | 0xfffffa8001bee7c5 |
Information | Value |
---|---|
Sequence Length | 177 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
IoAllocateMdl | VirtualAddress_ptr = 0x132f180, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efe180 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007efe180, MemoryDescriptorList_unk = 0xfffffa80025d0e70 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0e70 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
ObfReferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe |
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x132f180, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007eff180 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007eff180, MemoryDescriptorList_unk = 0xfffffa80025d0e70 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0e70 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x132f278, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x132f0d8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x4b0100, Length_ptr = 0x5e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x132f0a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x132ef08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x132f280, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x132f0a8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x132ef08, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x132f280, Length_ptr = 0xc8, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0xd4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x132f358, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa8001c02000+0x70 |
Start Address | 0xfffff800029ebb37 |
Information | Value |
---|---|
Sequence Length | 4 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x15c |
ProbeForRead | Address_ptr = 0x132e548, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2 |
Information | Value |
---|---|
Sequence Length | 6 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
KeRaiseIrqlToDpcLevel | ret_val_unk_out = 0x0 |
KeLowerIrql | NewIrql_unk = 0xfffffa8001c2bc00 |
KeGetCurrentIrql | ret_val_unk_out = 0x2 |
PsGetCurrentThreadId | ret_val_unk_out = 0x15c |
KeGetCurrentIrql | ret_val_unk_out = 0x0 |
Information | Value |
---|---|
Trigger | unknown_0xfffffa80031f3000+0x1a3 |
Start Address | 0xfffff800026d6184 |
Information | Value |
---|---|
Sequence Length | 35 |
Process | Amount |
---|---|
Process 18 (svchost.exe, PID: 264) | 1 |
Symbol | Parameters |
---|---|
PsGetCurrentProcess | ret_val_out = 0xfffffa8002f30350 |
IoAllocateMdl | VirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40 |
MmProbeAndLockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
MmMapLockedPagesSpecifyCache | MemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fd3ad0 |
MmUnmapLockedPages | BaseAddress_ptr = 0xfffff88007fd3ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40 |
MmUnlockPages | MemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40 |
IoFreeMdl | Mdl_unk = 0xfffffa80025d0f40 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
ProbeForRead | Address_ptr = 0x1a8ebc8, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
ProbeForRead | Address_ptr = 0x1a8ea28, Length_ptr = 0x30, Alignment = 0x4 |
ProbeForRead | Address_ptr = 0x48d4b0, Length_ptr = 0x5e, Alignment = 0x2 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
PsGetCurrentProcessId | ret_val_unk_out = 0x108 |
KeWaitForSingleObject | Object_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0 |
ObReferenceObjectByHandle | Handle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0 |
ObfDereferenceObject | Object_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1 |
KeWaitForSingleObject | Object_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0 |
KeReleaseMutex | Mutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0 |
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox
with deactivated setting "security.fileuri.strict_origin_policy".